CVE-2026-103519 Overview
CVE-2026-103519 affects the WP Ultimate Review plugin for WordPress in all versions up to and including 2.4.3. The plugin fails to validate user-supplied input before passing it to do_shortcode, enabling authenticated attackers with subscriber-level access to execute arbitrary shortcodes. The flaw abuses WordPress's strip_shortcodes() function, which unwraps the [[tag]] double-bracket escape into a bare [tag] that survives storage via wp_insert_post. The injected shortcode then fires when the publicly queryable xs_review post type is rendered through the_content. This issue is categorized under [CWE-94] Improper Control of Generation of Code.
Critical Impact
Authenticated subscriber-level users can trigger arbitrary shortcode execution on affected WordPress sites, enabling abuse of other installed plugins' shortcodes for information disclosure or site manipulation.
Affected Products
- WP Ultimate Review plugin for WordPress — all versions up to and including 2.4.3
- WordPress sites exposing the xs_review public post type
- Any WordPress installation where subscriber registration is enabled on an affected plugin version
Discovery Timeline
- 2026-10-03 - CVE-2026-103519 published to the National Vulnerability Database
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-103519
Vulnerability Analysis
The WP Ultimate Review plugin accepts review content from authenticated users and passes that content through do_shortcode without first stripping or neutralizing shortcode tokens. The plugin attempts to sanitize submissions by running the input through WordPress's strip_shortcodes() function. That function removes recognized shortcode patterns but also unwraps the standard double-bracket escape sequence [[tag]] into a single-bracket [tag] form. The unwrapped token then persists through wp_insert_post into the database.
When the xs_review custom post type is rendered on the front end, WordPress runs the stored content through the_content, which triggers do_shortcode and executes the attacker-planted token. Attackers can invoke any shortcode registered by WordPress core, the active theme, or other installed plugins. Impact depends on which shortcodes are available in the environment but commonly includes exposure of restricted content, user enumeration, or forced side effects from administrative shortcodes.
Root Cause
The root cause is improper input validation layered on top of an unsafe reliance on strip_shortcodes() as a security control. strip_shortcodes() was never designed as a sanitizer against shortcode injection and intentionally reverses the documented escape syntax. Review the plugin source at the vulnerable paths in content.php line 217, content.php line 347, and content.php line 366.
Attack Vector
An attacker registers or authenticates as a subscriber on a target site running an affected plugin version. The attacker submits a review containing a shortcode wrapped in double brackets, for example wrapping a target shortcode name in [[...]]. The plugin's sanitizer collapses the double brackets to single brackets, and the resulting token is stored as part of an xs_review post. When any visitor loads the rendered xs_review page, the_content executes the attacker's shortcode in the server context. See the Wordfence vulnerability report for additional detail.
Detection Methods for CVE-2026-103519
Indicators of Compromise
- xs_review posts authored by subscriber-level accounts that contain unexpected shortcode tokens in post_content
- Database rows in wp_posts where post_type = 'xs_review' and post_content matches shortcode patterns tied to admin-only or privileged plugins
- New or recently promoted subscriber accounts that submitted reviews shortly after registration
- Unexpected outbound requests or data exposure originating from pages that render the xs_review post type
Detection Strategies
- Query the WordPress database for xs_review posts containing bracketed tokens and audit each against the site's registered shortcodes
- Compare installed WP Ultimate Review versions against the vulnerable range (all versions through 2.4.3) across managed WordPress fleets
- Monitor web server access logs for POST requests to review submission endpoints followed by GET requests to xs_review permalinks
Monitoring Recommendations
- Alert on creation of xs_review posts by non-administrative users and review the content before publication
- Track plugin inventory changes and flag any site running WP Ultimate Review 2.4.3 or earlier
- Forward WordPress audit logs to a centralized logging platform and build detections for anomalous shortcode execution patterns
How to Mitigate CVE-2026-103519
Immediate Actions Required
- Update WP Ultimate Review to the patched release that supersedes 2.4.3 as published in the vendor changeset
- Audit the wp_posts table for malicious xs_review entries and delete or sanitize any that contain unauthorized shortcode tokens
- Review all subscriber-level accounts created in the window before patching and remove accounts that submitted suspicious reviews
- Temporarily disable public submission of reviews until the patched version is deployed
Patch Information
The plugin maintainer published a corrective changeset that revises the input handling path. Apply the fix tracked in the WP Ultimate Review changeset 3720426. Also review the initialization logic at init.php line 291 to confirm the patched code is active after upgrade.
Workarounds
- Deactivate the WP Ultimate Review plugin until the patched version can be deployed
- Restrict new user registration or require administrator approval for any role capable of submitting reviews
- Place a web application firewall rule in front of review submission endpoints that blocks requests containing [[ sequences in review body fields
- Remove the publicly_queryable capability from the xs_review post type via a register_post_type_args filter so stored content is not rendered through the_content
# Configuration example - disable the vulnerable plugin from WP-CLI
wp plugin deactivate wp-ultimate-review
wp plugin update wp-ultimate-review
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.