rootpwn

medium · CVSS v3 6.5 · EPSS 0.0028

CVE-2026-100157

WP Ultimate Review plugin up to 2.4.3 allows unauthenticated users to execute arbitrary shortcodes via the public review form, enabling remo

Overview

WP Ultimate Review plugin up to 2.4.3 allows unauthenticated users to execute arbitrary shortcodes via the public review form, enabling remote code execution on the site. The vulnerability stems from improper nonce validation and auto-publishing of submitted shortcodes. This can compromise site integrity and availability.

Description

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.

Impact

Confidentiality: attackers can read or exfiltrate site content. Integrity: malicious shortcodes can modify or delete content. Availability: site downtime or degraded performance. Defenders: WordPress site owners and administrators using the WP Ultimate Review plugin.

Remediation

Update the plugin to version 2.4.4 or later. If an update is not feasible, disable the review form or block shortcode execution by setting 'allow_shortcodes' to false. Ensure nonce validation is enforced and monitor for unexpected shortcode usage.

Risk context

Medium severity with a low EPSS score of 0.0028 indicates a moderate risk that is unlikely to be widely exploited, but timely patching is recommended to mitigate potential attacks.

Affected products

  • WordPress
  • WP Ultimate Review

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.5
CVSS v4
—
EPSS
0.0028

wordpress plugin arbitrary-code-execution shortcode unauthenticated wp-ultimate-review

← All CVEs