CVE-2026-101162
EUVD-2026-9193203.10.2026, 06:16
The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
Awaiting analysis
This vulnerability is currently awaiting analysis.