The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.

Project Subscriptions

Vendors Products
Wp Ultimate Review Subscribe
Wordpress-extensions Subscribe
Wp Ultimate Review Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 04 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Roxnor
Roxnor wp Ultimate Review
Wordpress-extensions
Wordpress-extensions wp Ultimate Review
Vendors & Products Roxnor
Roxnor wp Ultimate Review
Wordpress-extensions
Wordpress-extensions wp Ultimate Review

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.
Title WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.054Z

Reserved: 2026-09-25T12:18:04.662Z

Link: CVE-2026-100157

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:36.519Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:46.330

Modified: 2026-10-03T16:16:30.890

Link: CVE-2026-100157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T20:49:44Z

Weaknesses