Extension WordPress
Vulnérabilités WP Ultimate Review
Cette page rassemble les failles publiées pour WP Ultimate Review, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Ultimate Review
9 fiches
Ultimate Review <= 2.3.9 – Missing Authorization
The Ultimate Review plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-2.3.9
2.4.0
14/02/2026
Ultimate Review <= 2.3.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.3.7
2.3.8
07/12/2025
Wp Ultimate Review <= 2.2.5 – Unauthenticated Insecure Direct Object Reference
The WP Ultimate Review plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers…
*-2.2.5
2.3.0
17/04/2024
Wp Ultimate Review <= 2.2.5 – Missing Authorization
The Wp Ultimate Review plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wur_meta_box_content_save() function in versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers…
*-2.2.5
2.3.0
17/04/2024
Wp Ultimate Review <= 2.2.5 – Unauthenticated Review Restriction Bypass
The WP Ultimate Review plugin for WordPress is vulnerable to bypass review restrictions in all versions up to, and including, 2.2.5. This is due to the plugin not properly enforcing review restrictions. This makes it possible for unauthenticated…
*-2.2.5
2.3.0
17/04/2024
Wp Ultimate Review <= 2.3.6 – IP Spoofing
The WP Ultimate Review plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.3.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for…
*-2.3.6
2.3.7
05/01/2024
Wp Ultimate Review <= 2.3.0 – Cross-Site Request Forgery via wur_settings_view
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing nonce validation on the wur_settings_view() function. This makes it possible for unauthenticated attackers…
*-2.2.4
2.3.1
16/10/2023
Wp Ultimate Review <= 2.0.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Wp Ultimate Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-2.0.3
2.1.0
29/03/2023
Wp Ultimate Review <= 2.0.3 – Cross-Site Request Forgery
The Wp Ultimate Review plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing nonce validation on several functions like wur_settings_view(). This makes it possible for unauthenticated…
*-2.0.3
2.1.0
29/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.