WordPress Plugin Vulnerabilities

WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields

Description

The plugin does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.

Proof of Concept

Affects Plugins

Fixed in 12.7.12

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-09-24 (about 2 days ago)
Added
2026-09-24 (about 1 day ago)
Last Updated
2026-09-24 (about 1 day ago)

Other