CyberRota Analysis
AI-GeneratedThe wp-review-slider-pro plugin for WordPress versions prior to 12.7.12 is vulnerable due to a lack of capability checks on its AJAX handler for saving review submissions, allowing any authenticated user to overwrite live forms. This vulnerability can lead to Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be executed on public pages. WordPress site administrators, particularly those using this plugin, should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.