Cross-site Scripting Vulnerability in Rustaurius Ultimate Reviews Plugin
CVE-2025-49266
7.1HIGH
What is CVE-2025-49266?
A Cross-site Scripting (XSS) vulnerability has been identified in the Rustaurius Ultimate Reviews plugin, allowing attackers to inject malicious scripts into web pages viewed by users. This flaw could be exploited to execute arbitrary code in the context of a user’s browser, potentially leading to unauthorized actions and data breaches. The affected versions range from earlier releases to 3.2.14, highlighting the importance of updating to secure versions and employing best practices for web application security.
Affected Version(s)
Ultimate Reviews <= 3.2.14