plugin

Ultimate Reviews Vulnerabilities

13 known security issues reported for the Ultimate Reviews WordPress plugin. Most recent disclosed Jan 23, 2026.

1 critical 4 medium

Running Ultimate Reviews on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Reviews [ultimate-reviews] <= 3.2.16 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16.

Affected:
up to 3.2.16
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24634 on NVD →

Ultimate Reviews <= 3.2.16 - Unauthenticated Insecure Direct Object Reference

medium

The Ultimate Reviews plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.16
Fixed in:
3.2.17
Disclosed:
Jan 6, 2026

CVE-2026-24634 on NVD →

Ultimate Reviews [ultimate-reviews] < 3.2.15

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate Reviews allows Reflected XSS. This issue affects Ultimate Reviews: from n/a through 3.2.14.

Affected:
up to 3.2.15
Fixed in:
3.2.15
Disclosed:
Jun 17, 2025

CVE-2025-49266 on NVD →

Ultimate Reviews <= 3.2.14 - Reflected Cross-Site Scripting

medium

The Ultimate Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...

CVSS:
6.1
Affected:
up to 3.2.14
Fixed in:
3.2.15
Disclosed:
Jun 11, 2025

CVE-2025-49266 on NVD →

Ultimate Reviews [ultimate-reviews] < 3.2.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.

Affected:
up to 3.2.9
Fixed in:
3.2.9
Disclosed:
Mar 15, 2024

CVE-2024-25597 on NVD →

Ultimate Reviews <= 3.2.8 - Unauthenticated stored Cross-Site Scripting via reviews

medium

The Ultimate Reviews plugin for WordPress is vulnerable to stored Cross-Site Scripting via the review functionality in versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.1
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
Feb 12, 2024

CVE-2024-25597 on NVD →

Ultimate Reviews [ultimate-reviews] < 2.1.33

unknown

[en] The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.

Affected:
up to 2.1.33
Fixed in:
2.1.33
Disclosed:
Jun 7, 2023

CVE-2020-36726 on NVD →

Ultimate Reviews [ultimate-reviews] < 3.0.16

unknown

[en] Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

Affected:
up to 3.0.16
Fixed in:
3.0.16
Disclosed:
Jan 28, 2022

CVE-2022-23979 on NVD →

Ultimate Reviews <= 3.0.15 - Authenticated Stored Cross-Site Scripting

medium

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

CVSS:
4.8
Affected:
up to 3.0.15
Fixed in:
3.0.16
Disclosed:
Jan 6, 2022

CVE-2022-23979 on NVD →

Ultimate Reviews < 2.1.33 - PHP Object Injection

critical

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.

CVSS:
9.8
Affected:
up to 2.1.33
Fixed in:
2.1.33
Disclosed:
Nov 10, 2020

CVE-2020-36726 on NVD →

Ultimate Reviews [ultimate-reviews] < 2.1.33

unknown

Insecure Deserialization vulnerability leading to unauthenticated PHP object injection found by Jerome Bruandet (NinTechNet) in WordPress Ultimate Reviews plugin (versions <= 2.1.32).

Affected:
up to 2.1.33
Fixed in:
2.1.33
Disclosed:
Nov 10, 2020

Ultimate Reviews [ultimate-reviews] < 2.1.33

unknown

The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.

Affected:
up to 2.1.33
Fixed in:
2.1.33
Disclosed:
Nov 10, 2020

Ultimate Reviews [ultimate-reviews] < 2.1.33

unknown

There were three occurrences in the plugin where an unauthenticated user could inject a serialized PHP object via a cookie, which could potentially lead to a PHP object injection vulnerability.

Affected:
up to 2.1.33
Fixed in:
2.1.33

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database