WordPress 插件 WP Ultimate Review 在所有 2.4.3 及更低版本中存在任意短代码执行漏洞。该漏洞源于软件在未对值进行充分验证的情况下便执行了 函数,允许用户触发不当操作。这使得拥有订阅者级别及以上权限的已认证攻击者能够执行任意短代码。该利用方式依赖于 WordPress 内置的 函数将双括号转义格式 剥离为裸形式的 ,该形式在通过 存储时得以保留,并在通过 钩子渲染公共可查询的 文章类型时被触发执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | WP Ultimate Review | 0 ~ 2.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100157 | 6.5 MEDIUM | WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_ |
| CVE-2026-97344 | 6.4 MEDIUM | Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored |
No comments yet