plugin

Wp Ultimate Review Vulnerabilities

17 known security issues reported for the Wp Ultimate Review WordPress plugin. Most recent disclosed Feb 14, 2026.

9 medium

Running Wp Ultimate Review on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Review <= 2.3.9 - Missing Authorization

medium

The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.3.9
Fixed in:
2.4.0
Disclosed:
Feb 14, 2026

CVE-2026-39644 on NVD →

WP Ultimate Review [wp-ultimate-review] <= 2.3.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.6.

Affected:
up to 2.3.6
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63057 on NVD →

Ultimate Review <= 2.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Dec 7, 2025

CVE-2025-63057 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.3.0

unknown

[en] Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
May 17, 2024

CVE-2024-32685 on NVD →

WP Ultimate Review [wp-ultimate-review] <= 2.3.6 (unfixed)

unknown

[en] Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.

Affected:
up to 2.3.6
Fix:
No patched version reported
Disclosed:
May 17, 2024

CVE-2024-21746 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.3.0

unknown

[en] Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Apr 22, 2024

CVE-2024-32684 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.3.0

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Apr 19, 2024

CVE-2024-32683 on NVD →

Wp Ultimate Review <= 2.2.5 - Missing Authorization

medium

The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wur_meta_box_content_save() function in versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to leave reviews on password protected posts.

CVSS:
5.3
Affected:
up to 2.2.5
Fixed in:
2.3.0
Disclosed:
Apr 17, 2024

CVE-2024-32684 on NVD →

Wp Ultimate Review <= 2.2.5 - Unauthenticated Review Restriction Bypass

medium

The WP Ultimate Review plugin for WordPress is vulnerable to bypass review restrictions in all versions up to, and including, 2.2.5. This is due to the plugin not properly enforcing review restrictions. This makes it possible for unauthenticated attackers to review things multiple times.

CVSS:
5.3
Affected:
up to 2.2.5
Fixed in:
2.3.0
Disclosed:
Apr 17, 2024

CVE-2024-32685 on NVD →

Wp Ultimate Review <= 2.2.5 - Unauthenticated Insecure Direct Object Reference

medium

The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.2.5
Fixed in:
2.3.0
Disclosed:
Apr 17, 2024

CVE-2024-32683 on NVD →

Wp Ultimate Review <= 2.3.6 - IP Spoofing

medium

The WP Ultimate Review plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.3.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass IP rate lim...

CVSS:
5.3
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Jan 5, 2024

CVE-2024-21746 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.1.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Nov 12, 2023

CVE-2023-28987 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.3.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.

Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Oct 22, 2023

CVE-2023-46085 on NVD →

Wp Ultimate Review <= 2.3.0 - Cross-Site Request Forgery via wur_settings_view

medium

The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing nonce validation on the wur_settings_view() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted...

CVSS:
4.3
Affected:
up to 2.2.4
Fixed in:
2.3.1
Disclosed:
Oct 16, 2023

CVE-2023-46085 on NVD →

WP Ultimate Review [wp-ultimate-review] < 2.1.0

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Jun 23, 2023

CVE-2023-28751 on NVD →

Wp Ultimate Review <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 2.0.3
Fixed in:
2.1.0
Disclosed:
Mar 29, 2023

CVE-2023-28751 on NVD →

Wp Ultimate Review <= 2.0.3 - Cross-Site Request Forgery

medium

The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing nonce validation on several functions like wur_settings_view(). This makes it possible for unauthenticated attackers to perform unauthorized actions like modifying the...

CVSS:
4.3
Affected:
up to 2.0.3
Fixed in:
2.1.0
Disclosed:
Mar 29, 2023

CVE-2023-28987 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database