Arbitrary Shortcode Execution in WP Ultimate Review Plugin for WordPress
CVE-2026-100157

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-100157?

The WP Ultimate Review plugin for WordPress has a vulnerability that allows arbitrary shortcode execution due to improper validation of user inputs. This issue affects all versions up to 2.4.3, where unauthenticated attackers can exploit the vulnerability by submitting malicious shortcodes through the public review form. The nonce needed for verification is exposed to all users, allowing attackers to bypass security mechanisms and auto-publish malicious shortcodes without any administrative oversight. This vulnerability poses significant risks as it can enable unauthorized actions within WordPress sites.

Affected Version(s)

WP Ultimate Review 0 <= 2.4.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

walid213
.