Junglewise Threat Intelligence

CVE-2026-84095: WordPress WP Review Slider Pro stored cross-site scripting in AJAX handler

CVE-2026-84095 · Severity: info · Published 2026-09-26

Executive brief

WP Review Slider Pro is a WordPress plugin for displaying customer reviews. The plugin fails to properly restrict who can submit reviews via its AJAX endpoint, allowing any logged-in user to inject malicious scripts that execute in the browsers of site visitors viewing public review pages. An attacker with a basic subscriber account can exploit this to steal credentials, deface content, or redirect users to malicious sites.

Technical details

The plugin's AJAX handler for storing review content lacks capability checks and uses a globally-generated nonce, allowing any authenticated user to submit arbitrary review data. Stored XSS occurs because the injected review content is later rendered on public pages without output encoding. Exploitation requires authentication (subscriber level) and CSRF-token access, but no user interaction is needed for the XSS to execute against other visitors.

Affected products

  • WP Review Slider Pro WP Review Slider Pro before 12.7.12

Timeline

  • 2026-09-24: disclosed
  • 2026-09-24: patched: Fixed in version 12.7.12

References

Related threats