CVE-2026-101161
The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.
- Published Oct 3, 2026
- CVSS 7.5 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available