OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92412

HIGH · CVSS 7.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Five Star Restaurant Reviews WordPress plugin prior to version 2.3.14 is vulnerable to cross-site scripting (XSS) due to improper escaping of user-supplied values in HTML output. This flaw allows unauthenticated attackers to inject malicious scripts that execute in the browsers of users, including administrators, who interact with the compromised content. WordPress site administrators and users of this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-92412
Severity
HIGH
CVSS
7.1
EPSS
0.16%
WordPress

Original NVD Description

The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.