Stored Cross-Site Scripting Vulnerability in WP Yelp Review Slider Plugin for WordPress
CVE-2026-93778

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93778?

The WP Yelp Review Slider plugin for WordPress has a vulnerability that allows attackers to exploit insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary web scripts through Yelp review text, impacting all versions up to and including 9.2. This occurs when an administrator utilizes the plugin’s Download Reviews feature, unintentionally introducing malicious payloads into the database. The attack leverages reviews from anonymous Yelp users, allowing harmful scripts to execute when victims access compromised pages without any need for a WordPress account.

Affected Version(s)

WP Yelp Review Slider 0 <= 9.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivaylo
.