CVE-2026-84095: WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import

Published Sep 26, 2026
·
Updated

The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.

Affected Software

1 affected component
WP Review Slider Pro<12.7.12

Event History

Sep 26, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user can exploit it, including users with only the Subscriber role. The affected AJAX handler lacks a capability check, and its nonce is available to every visitor.

2

Does exploitation require the attacker to be able to publish content directly?

No. A low-privileged authenticated user can submit arbitrary review content through the vulnerable review-import functionality, which is later rendered on public pages without escaping.

3

Who is exposed to the stored script payload?

Visitors to public pages that display the attacker-controlled imported review content may execute the stored script in their browser.

4

How can administrators determine whether they may be affected?

Sites using WP Review Slider Pro versions earlier than 12.7.12 may be affected. Administrators should also review imported review content for unexpected or suspicious markup or scripts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203