CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-101161: WP Ultimate Review 0 to before 2.4.4

CVE-2026-101161. CVSS 3.1 base score 7.5 (HIGH, Source advisory). EPSS 0.00338 (percentile 0.24979), scored 04-Oct-2026.

Affected technology

WP Ultimate Review · 0 to before 2.4.4
Vendor not specified by the source

Description’s affected range: before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. Source advisory’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-400
CCR priority
30.1 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Source advisory
EPSS
0.00338 · percentile 0.25293 · 2026-10-10
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-101161.html