Plugin Vulnerability Hub
Plugin 9 known issues Latest disclosed Feb 14, 2026

WP Ultimate Review Vulnerabilities

Review known vulnerability records for the WordPress plugin WP Ultimate Review (`wp-ultimate-review`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-39644, CVE-2025-63057 and CVE-2024-32683, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
9
High or Critical
0
Patch Coverage
100%
Last Updated
Apr 16, 2026
Priority CVE Quick Links

Fast paths into WP Ultimate Review CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
9
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WP Ultimate Review so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
9 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-39644, CVE-2025-63057 and CVE-2024-32683
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for WP Ultimate Review

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: No CVE-2026-39644
CVE-2026-39644: Ultimate Review <= 2.3.9 - Missing Authorization

The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Feb 14, 2026
Patched Release
Not published
Affected Versions
Versions up to 2.3.9
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-63057
CVE-2025-63057: Ultimate Review <= 2.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...

Published
Dec 07, 2025
Patched Release
2.3.8
Affected Versions
Versions up to 2.3.7
Next Step
Update to 2.3.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-32683
CVE-2024-32683: Wp Ultimate Review <= 2.2.5 - Unauthenticated Insecure Direct Object Reference

The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Apr 17, 2024
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.5
Next Step
Update to 2.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-32684
CVE-2024-32684: Wp Ultimate Review <= 2.2.5 - Missing Authorization

The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wur_meta_box_content_save() function in versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to leave reviews on...

Published
Apr 17, 2024
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.5
Next Step
Update to 2.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-32685
CVE-2024-32685: Wp Ultimate Review <= 2.2.5 - Unauthenticated Review Restriction Bypass

The WP Ultimate Review plugin for WordPress is vulnerable to bypass review restrictions in all versions up to, and including, 2.2.5. This is due to the plugin not properly enforcing review restrictions. This makes it possible for unauthenticated attackers to review things multipl...

Published
Apr 17, 2024
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.5
Next Step
Update to 2.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-21746
CVE-2024-21746: Wp Ultimate Review <= 2.3.6 - IP Spoofing

The WP Ultimate Review plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.3.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthe...

Published
Jan 05, 2024
Patched Release
2.3.7
Affected Versions
Versions up to 2.3.6
Next Step
Update to 2.3.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-46085
CVE-2023-46085: Wp Ultimate Review <= 2.3.0 - Cross-Site Request Forgery via wur_settings_view

The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing nonce validation on the wur_settings_view() function. This makes it possible for unauthenticated attackers to modify the plugin'...

Published
Oct 16, 2023
Patched Release
2.3.1
Affected Versions
Versions up to 2.2.4
Next Step
Update to 2.3.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-28751
CVE-2023-28751: Wp Ultimate Review <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...

Published
Mar 29, 2023
Patched Release
2.1.0
Affected Versions
Versions up to 2.0.3
Next Step
Update to 2.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-28987
CVE-2023-28987: Wp Ultimate Review <= 2.0.3 - Cross-Site Request Forgery

The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing nonce validation on several functions like wur_settings_view(). This makes it possible for unauthenticated attackers to perform...

Published
Mar 29, 2023
Patched Release
2.1.0
Affected Versions
Versions up to 2.0.3
Next Step
Update to 2.1.0 or newer if supported.