WordPress Plugin Vulnerabilities
WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating
Description
The plugin does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Alban Roche
Submitter
Alban Roche
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)