CVE-2026-101160: WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating
The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Ultimate Reviewto a version that resolves this vulnerability.Fixed in 2.4.4