CVE-2026-92412: Five Star Restaurant Reviews < 2.3.14 - Reflected XSS
Published Oct 1, 2026
·Updated
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
Affected Software
1 affected component
WordPress Five Star Restaurant Reviews<2.3.14
Event History
Oct 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue, and what interaction is required?
An unauthenticated attacker can exploit it by getting a victim to submit a crafted request. The injected script then runs in the victim's browser, including when the victim is a logged-in WordPress administrator.
2
Which plugin versions are affected?
Versions of Five Star Restaurant Reviews before 2.3.14 are affected. Updating to version 2.3.14 or later addresses the affected version range.