Ultimate Review <= 2.3.9 - Missing Authorization
medium
The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.3.9
- Fixed in:
- 2.4.0
- Disclosed:
- Feb 14, 2026
CVE-2026-39644 on NVD →
WP Ultimate Review [wp-ultimate-review] <= 2.3.6 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.6.
- Affected:
- up to 2.3.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63057 on NVD →
Ultimate Review <= 2.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Dec 7, 2025
CVE-2025-63057 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.3.0
unknown
[en] Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- May 17, 2024
CVE-2024-32685 on NVD →
WP Ultimate Review [wp-ultimate-review] <= 2.3.6 (unfixed)
unknown
[en] Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.
- Affected:
- up to 2.3.6
- Fix:
- No patched version reported
- Disclosed:
- May 17, 2024
CVE-2024-21746 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.3.0
unknown
[en] Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 22, 2024
CVE-2024-32684 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.3.0
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 19, 2024
CVE-2024-32683 on NVD →
Wp Ultimate Review <= 2.2.5 - Missing Authorization
medium
The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wur_meta_box_content_save() function in versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to leave reviews on password protected posts.
- CVSS:
- 5.3
- Affected:
- up to 2.2.5
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 17, 2024
CVE-2024-32684 on NVD →
Wp Ultimate Review <= 2.2.5 - Unauthenticated Review Restriction Bypass
medium
The WP Ultimate Review plugin for WordPress is vulnerable to bypass review restrictions in all versions up to, and including, 2.2.5. This is due to the plugin not properly enforcing review restrictions. This makes it possible for unauthenticated attackers to review things multiple times.
- CVSS:
- 5.3
- Affected:
- up to 2.2.5
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 17, 2024
CVE-2024-32685 on NVD →
Wp Ultimate Review <= 2.2.5 - Unauthenticated Insecure Direct Object Reference
medium
The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.2.5
- Fixed in:
- 2.3.0
- Disclosed:
- Apr 17, 2024
CVE-2024-32683 on NVD →
Wp Ultimate Review <= 2.3.6 - IP Spoofing
medium
The WP Ultimate Review plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.3.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP rate lim...
- CVSS:
- 5.3
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.7
- Disclosed:
- Jan 5, 2024
CVE-2024-21746 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.1.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Nov 12, 2023
CVE-2023-28987 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.3.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Oct 22, 2023
CVE-2023-46085 on NVD →
Wp Ultimate Review <= 2.3.0 - Cross-Site Request Forgery via wur_settings_view
medium
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing nonce validation on the wur_settings_view() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 2.2.4
- Fixed in:
- 2.3.1
- Disclosed:
- Oct 16, 2023
CVE-2023-46085 on NVD →
WP Ultimate Review [wp-ultimate-review] < 2.1.0
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Jun 23, 2023
CVE-2023-28751 on NVD →
Wp Ultimate Review <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...
- CVSS:
- 4.4
- Affected:
- up to 2.0.3
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 29, 2023
CVE-2023-28751 on NVD →
Wp Ultimate Review <= 2.0.3 - Cross-Site Request Forgery
medium
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing nonce validation on several functions like wur_settings_view(). This makes it possible for unauthenticated attackers to perform unauthorized actions like modifying the...
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.1.0
- Disclosed:
- Mar 29, 2023
CVE-2023-28987 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database