CVE-2026-39644: WordPress Wp Ultimate Review plugin <= 2.3.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wp Ultimate Review: from n/a through <= 2.3.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Roxnor Wp Ultimate Review (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.3.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39644?
CVE-2026-39644 has been classified as a high-severity broken access control vulnerability.
How do I fix CVE-2026-39644?
To mitigate CVE-2026-39644, update the WP Ultimate Review plugin to the latest version beyond 2.3.8.
What versions of WP Ultimate Review are affected by CVE-2026-39644?
CVE-2026-39644 affects WP Ultimate Review plugin versions 2.3.8 and earlier.
What type of vulnerability is CVE-2026-39644?
CVE-2026-39644 is a broken access control vulnerability that allows unauthorized access due to misconfigured security levels.
Who is the vendor for the affected WP Ultimate Review plugin in CVE-2026-39644?
The vendor for the affected WP Ultimate Review plugin in CVE-2026-39644 is Roxnor.