Junglewise Threat Intelligence

CVE-2026-84096: WP Review Slider Pro stored XSS via review form fields

CVE-2026-84096 · Severity: info · Published 2026-09-26

Executive brief

The WP Review Slider Pro WordPress plugin fails to properly restrict who can modify review forms on websites. An attacker with a basic subscriber account can inject malicious code into live review forms that gets displayed to all site visitors without being sanitized, allowing them to steal credentials or perform actions on behalf of other users.

Technical details

The plugin's AJAX handler for saving review submissions lacks capability checks and generates nonces for all visitors, allowing any authenticated user to overwrite form fields. Injected values are output without escaping on public pages, resulting in Stored XSS. This requires authentication as a subscriber or higher role.

Affected products

  • WP Review Slider Pro WP Review Slider Pro before 12.7.12

Timeline

  • 2026-09-24: disclosed
  • 2026-09-24: patched: Fixed in version 12.7.12

References

Related threats