All 4 CVE vulnerabilities found in Ultimate Reviews, with AI-generated Chinese analysis, references, and POCs.
Vendor: rustaurius
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-24634 | WordPress Ultimate Reviews plugin <= 3.2.16 - Insecure Direct Object References (IDOR) vulnerability CWE-639 | 8.1 | - | 2026-01-23 |
| CVE-2025-49266 | WordPress Ultimate Reviews plugin <= 3.2.14 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2025-06-17 |
| CVE-2024-25597 | WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2024-03-15 |
| CVE-2020-36726 | Ultimate Reviews < 2.1.33 - PHP Object Injection CWE-502 | 9.8 | Critical | 2023-06-07 |
All 4 known CVE vulnerabilities affecting Ultimate Reviews with full Chinese analysis, references, and POCs where available.