CVE-2026-24634: WordPress Ultimate Reviews plugin <= 3.2.16 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24634?
CVE-2026-24634 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2026-24634?
The recommended fix for CVE-2026-24634 is to update the Rustaurius Ultimate Reviews plugin to version 3.2.17 or later.
What type of vulnerability is CVE-2026-24634?
CVE-2026-24634 is an Insecure Direct Object References (IDOR) vulnerability that allows an authorization bypass through user-controlled keys.
Which versions of the Ultimate Reviews plugin are affected by CVE-2026-24634?
CVE-2026-24634 affects versions of the Ultimate Reviews plugin up to and including 3.2.16.
Who is impacted by CVE-2026-24634?
Any WordPress site using the Rustaurius Ultimate Reviews plugin version 3.2.16 or earlier is at risk due to CVE-2026-24634.