Skip to main content
Vulnerability Database/CVE-2026-100157

CVE-2026-100157: WP Ultimate Review Plugin RCE Vulnerability

CVE-2026-100157 is an arbitrary shortcode execution flaw in WP Ultimate Review plugin for WordPress allowing unauthenticated attackers to execute arbitrary code. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-100157 Overview

CVE-2026-100157 is an arbitrary shortcode execution vulnerability in the WP Ultimate Review plugin for WordPress. The flaw affects all versions up to and including 2.4.3. The plugin fails to validate values before passing them to the do_shortcode function, enabling unauthenticated attackers to execute arbitrary shortcodes on vulnerable sites. The nonce required to pass the only gate is emitted to unauthenticated visitors through the public review form. Submitted shortcode payloads are auto-published without administrator approval by default, which removes any need for privileged interaction. The issue is tracked under CWE-94: Improper Control of Generation of Code.

Critical Impact

Unauthenticated attackers can execute arbitrary WordPress shortcodes, potentially disclosing information or triggering actions exposed by any installed shortcode-emitting plugin.

Affected Products

  • WordPress plugin: WP Ultimate Review
  • All versions up to and including 2.4.3
  • WordPress sites using the plugin's public review form with default auto-publish settings

Discovery Timeline

  • 2026-10-03 - CVE-2026-100157 published to the National Vulnerability Database
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-100157

Vulnerability Analysis

The vulnerability resides in the WP Ultimate Review plugin's review submission handling logic. Code referenced in app/content.php (lines 52, 217, and 347) and init.php (line 286) accepts user-supplied input and passes it to WordPress's do_shortcode function without validating that the value corresponds to an allow-listed shortcode. Because the plugin exposes the required nonce through the public-facing review form, any unauthenticated visitor can retrieve a valid token and submit a crafted payload. With the default configuration, submitted content is auto-published without moderator approval, so the shortcode is rendered against site visitors as if authored by the site itself. The impact scope depends on which shortcodes are registered by other plugins or themes on the target site.

Root Cause

The root cause is improper input validation [CWE-94]. The plugin treats a user-controlled parameter as trusted shortcode content and invokes do_shortcode without constraining the set of permissible shortcodes or stripping unregistered tags. Nonce verification alone does not constitute authorization when the nonce is handed to anonymous visitors.

Attack Vector

An unauthenticated attacker loads the public review form to obtain a valid WordPress nonce. The attacker then submits a review containing arbitrary shortcode syntax, which the plugin stores and auto-publishes. When the review is rendered, do_shortcode executes the attacker-supplied shortcodes server-side. Depending on installed plugins, this can lead to information disclosure, enumeration of restricted content, or invocation of unintended plugin functionality. See the Wordfence Vulnerability Report and the vulnerable code in the WP Ultimate Review source for technical details.

Detection Methods for CVE-2026-100157

Indicators of Compromise

  • Published reviews whose content contains WordPress shortcode syntax ([shortcode_name ...]) that was not sanctioned by site administrators.
  • Unusual HTTP POST requests to the WP Ultimate Review submission endpoint from unauthenticated clients, especially bursts from a single IP address.
  • Rendered review pages invoking shortcodes registered by unrelated plugins such as file listers, user enumerators, or private content viewers.

Detection Strategies

  • Audit the wp_posts table for review content containing [ and ] bracket patterns matching known shortcode names.
  • Review web server access logs for anonymous POST requests to the plugin's review submission URL immediately preceded by a GET of the review form.
  • Enable WordPress debug logging to capture unexpected do_shortcode invocations originating from review content.

Monitoring Recommendations

  • Alert on new published posts of the plugin's review post type when the author is unauthenticated or anonymous.
  • Monitor outbound responses from pages hosting the review form for content produced by sensitive shortcodes.
  • Track plugin version coverage across managed WordPress sites to identify instances still running 2.4.3 or earlier.

How to Mitigate CVE-2026-100157

Immediate Actions Required

  • Update the WP Ultimate Review plugin to a version newer than 2.4.3 as soon as the vendor publishes a fixed release.
  • Disable the plugin on affected sites if an updated version is not yet available.
  • Enable manual moderation of submitted reviews so no user-supplied content is auto-published.

Patch Information

Review the vendor's remediation in the WP Ultimate Review changeset. Administrators should apply the latest plugin release through the WordPress admin dashboard or by replacing the plugin files from the official repository. After updating, confirm the installed version is higher than 2.4.3 under Plugins → Installed Plugins.

Workarounds

  • Configure the plugin to require administrator approval before publishing any review, eliminating automatic rendering of attacker-supplied content.
  • Deploy a web application firewall rule that blocks POST requests to the review submission endpoint containing shortcode bracket syntax.
  • Restrict access to the public review form through authentication or IP allow-listing until a patched version is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.