CVE-2026-101161: WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode
The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this denial of service?
Sites using WP Ultimate Review versions before 2.4.4 are exposed when the plugin's review display settings have never been saved. The affected reviewed page can then fail with a fatal error on every subsequent visit.
Does exploitation require authentication?
No. An unauthenticated attacker can store crafted review content that triggers the persistent failure.
What condition makes this issue exploitable?
The plugin's review display settings must never have been saved. Saving those settings is identified as the relevant configuration condition, while upgrading to 2.4.4 or later addresses the affected version range.