---
id: CVE-2026-101160
title: >-
  The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a
  submitted review rating is numeric before storing it and later using it in
  numeric operations when rendering reviews, allowing unauthenticated users to
  make th…
summary: >-
  The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a
  submitted review rating is numeric before storing it and later using it in
  numeric operations when rendering reviews, allowing unauthenticated users to
  make th…
severity: none
cwe:
  - CWE-400
product: WP Ultimate Review
affected:
  - wp_ultimate_review < 2.4.4
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:38.350'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101160'
references:
  - url: 'https://wpscan.com/vulnerability/d728523f-1f33-470f-b64f-e9e286d29b6b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.557Z'
---

## Overview

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
