Executive brief
The Wp Ultimate Review plugin for WordPress, which allows site owners to create and manage product reviews, contains a security flaw in its access control system. This vulnerability could allow unauthorized individuals to bypass intended security levels and perform actions or access information they should not be able to. This could lead to unauthorized modifications to review content or exposure of internal site data.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Roxnor Wp Ultimate Review plugin for WordPress through version 2.3.9. The flaw stems from incorrectly configured access control security levels within the plugin's functions. An unauthenticated remote attacker can exploit this lack of validation to execute actions or access data that should be restricted to higher-privileged users. The vulnerability is addressed in version 2.4.0.
Affected products
- Roxnor Wp Ultimate Review <= 2.3.9
Timeline
- 2026-01-15: other: Vulnerability reported by researcher hhhai
- 2026-02-14: advisory: Patchstack published initial advisory
- 2026-04-08: disclosed: CVE-2026-39644 published
- 2026-02-14: patched: Version 2.4.0 released to address the issue