Arbitrary Shortcode Execution in WP Ultimate Review Plugin for WordPress
CVE-2026-100157
6.5MEDIUM
What is CVE-2026-100157?
The WP Ultimate Review plugin for WordPress has a vulnerability that allows arbitrary shortcode execution due to improper validation of user inputs. This issue affects all versions up to 2.4.3, where unauthenticated attackers can exploit the vulnerability by submitting malicious shortcodes through the public review form. The nonce needed for verification is exposed to all users, allowing attackers to bypass security mechanisms and auto-publish malicious shortcodes without any administrative oversight. This vulnerability poses significant risks as it can enable unauthorized actions within WordPress sites.
Affected Version(s)
WP Ultimate Review 0 <= 2.4.3