Executive brief
The WP Ultimate Review plugin for WordPress allows authenticated attackers with subscriber-level access to execute arbitrary shortcodes without proper validation. An attacker could exploit this to run malicious code, potentially compromising the WordPress site's functionality, data, or integrity.
Technical details
The vulnerability stems from insufficient input validation before calling do_shortcode() in an action handler. Authenticated users with subscriber-level or higher permissions can trigger execution of unvalidated shortcodes, allowing arbitrary code execution within the WordPress context. The flaw affects all versions up to and including 2.4.2.
Affected products
- WP Ultimate Review WP Ultimate Review up to and including 2.4.2
Timeline
- 2026-09-22: disclosed