Junglewise Threat Intelligence

CVE-2026-92235: WP Ultimate Review arbitrary shortcode execution

CVE-2026-92235 · Severity: high · CVSS 8.1 · Published 2026-09-22

Executive brief

The WP Ultimate Review plugin for WordPress allows authenticated attackers with subscriber-level access to execute arbitrary shortcodes without proper validation. An attacker could exploit this to run malicious code, potentially compromising the WordPress site's functionality, data, or integrity.

Technical details

The vulnerability stems from insufficient input validation before calling do_shortcode() in an action handler. Authenticated users with subscriber-level or higher permissions can trigger execution of unvalidated shortcodes, allowing arbitrary code execution within the WordPress context. The flaw affects all versions up to and including 2.4.2.

Affected products

  • WP Ultimate Review WP Ultimate Review up to and including 2.4.2

Timeline

  • 2026-09-22: disclosed

References