Ultimate Reviews [ultimate-reviews] <= 3.2.16 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16.
- Affected:
- up to 3.2.16
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24634 on NVD →
Ultimate Reviews <= 3.2.16 - Unauthenticated Insecure Direct Object Reference
medium
The Ultimate Reviews plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.16 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.17
- Disclosed:
- Jan 6, 2026
CVE-2026-24634 on NVD →
Ultimate Reviews [ultimate-reviews] < 3.2.15
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate Reviews allows Reflected XSS. This issue affects Ultimate Reviews: from n/a through 3.2.14.
- Affected:
- up to 3.2.15
- Fixed in:
- 3.2.15
- Disclosed:
- Jun 17, 2025
CVE-2025-49266 on NVD →
Ultimate Reviews <= 3.2.14 - Reflected Cross-Site Scripting
medium
The Ultimate Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...
- CVSS:
- 6.1
- Affected:
- up to 3.2.14
- Fixed in:
- 3.2.15
- Disclosed:
- Jun 11, 2025
CVE-2025-49266 on NVD →
Ultimate Reviews [ultimate-reviews] < 3.2.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8.
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
- Disclosed:
- Mar 15, 2024
CVE-2024-25597 on NVD →
Ultimate Reviews <= 3.2.8 - Unauthenticated stored Cross-Site Scripting via reviews
medium
The Ultimate Reviews plugin for WordPress is vulnerable to stored Cross-Site Scripting via the review functionality in versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.1
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.9
- Disclosed:
- Feb 12, 2024
CVE-2024-25597 on NVD →
Ultimate Reviews [ultimate-reviews] < 2.1.33
unknown
[en] The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
- Affected:
- up to 2.1.33
- Fixed in:
- 2.1.33
- Disclosed:
- Jun 7, 2023
CVE-2020-36726 on NVD →
Ultimate Reviews [ultimate-reviews] < 3.0.16
unknown
[en] Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
- Affected:
- up to 3.0.16
- Fixed in:
- 3.0.16
- Disclosed:
- Jan 28, 2022
CVE-2022-23979 on NVD →
Ultimate Reviews <= 3.0.15 - Authenticated Stored Cross-Site Scripting
medium
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
- CVSS:
- 4.8
- Affected:
- up to 3.0.15
- Fixed in:
- 3.0.16
- Disclosed:
- Jan 6, 2022
CVE-2022-23979 on NVD →
Ultimate Reviews < 2.1.33 - PHP Object Injection
critical
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
- CVSS:
- 9.8
- Affected:
- up to 2.1.33
- Fixed in:
- 2.1.33
- Disclosed:
- Nov 10, 2020
CVE-2020-36726 on NVD →
Ultimate Reviews [ultimate-reviews] < 2.1.33
unknown
Insecure Deserialization vulnerability leading to unauthenticated PHP object injection found by Jerome Bruandet (NinTechNet) in WordPress Ultimate Reviews plugin (versions <= 2.1.32).
- Affected:
- up to 2.1.33
- Fixed in:
- 2.1.33
- Disclosed:
- Nov 10, 2020
Ultimate Reviews [ultimate-reviews] < 2.1.33
unknown
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
- Affected:
- up to 2.1.33
- Fixed in:
- 2.1.33
- Disclosed:
- Nov 10, 2020
Ultimate Reviews [ultimate-reviews] < 2.1.33
unknown
There were three occurrences in the plugin where an unauthenticated user could inject a serialized PHP object via a cookie, which could potentially lead to a PHP object injection vulnerability.
- Affected:
- up to 2.1.33
- Fixed in:
- 2.1.33
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database