---
id: CVE-2026-92235
title: >-
  The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary
  shortcode execution in all versions up to, and including, 2.4.2
summary: >-
  The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary
  shortcode execution in all versions up to, and including, 2.4.2. This is due
  to the software allowing users to execute an action that does not properly
  validate a…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-94
vendor: roxnor
product: WP Ultimate Review
affected:
  - wp_ultimate_review <= 2.4.2
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:04:55.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92235'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/app/content.php#L189
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/app/content.php#L341
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/app/content.php#L360
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/app/content.php#L56
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/init.php#L271
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-ultimate-review/tags/2.4.2/views/public/meta-box-user-review.php#L538
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3703958%40wp-ultimate-review&new=3703958%40wp-ultimate-review
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/dc0fe855-97b7-46ef-b1c8-1602447e97e6?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T10:08:59.756351Z'
ingestedAt: '2026-09-22T08:00:27.691Z'
epss: 0.00361
epssPercentile: 0.27176
---

## Overview

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
