What this page helps you verify fast
This hub clusters every indexed record for WP Ultimate Review so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin WP Ultimate Review (`wp-ultimate-review`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-39644, CVE-2025-63057 and CVE-2024-32683, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
Ultimate Review <= 2.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ultimate Review <= 2.3.9 - Missing Authorization
Wp Ultimate Review <= 2.2.5 - Unauthenticated Insecure Direct Object Reference
Wp Ultimate Review <= 2.2.5 - Missing Authorization
Wp Ultimate Review <= 2.2.5 - Unauthenticated Review Restriction Bypass
Wp Ultimate Review <= 2.3.6 - IP Spoofing
Wp Ultimate Review <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Wp Ultimate Review <= 2.3.0 - Cross-Site Request Forgery via wur_settings_view
This hub clusters every indexed record for WP Ultimate Review so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible...
The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This...
The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key....
Sorted by latest disclosure date so newly published issues surface first.
The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, t...
The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wur_meta_box_content_save() function in versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to leave reviews on...
The WP Ultimate Review plugin for WordPress is vulnerable to bypass review restrictions in all versions up to, and including, 2.2.5. This is due to the plugin not properly enforcing review restrictions. This makes it possible for unauthenticated attackers to review things multipl...
The WP Ultimate Review plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.3.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthe...
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing nonce validation on the wur_settings_view() function. This makes it possible for unauthenticated attackers to modify the plugin'...
The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing nonce validation on several functions like wur_settings_view(). This makes it possible for unauthenticated attackers to perform...