CVE-2026-94078: WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
Affected Software
1 affected component
WordPress Site Reviews<=8.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Site Reviews pluginto a version that resolves this vulnerability.Fixed in 8.3.2
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The vulnerability is rated as exploitable over the network with low attack complexity and requires no privileges. Exploitation does require user interaction.
2
What is the potential impact if exploitation succeeds?
The CVSS vector indicates low impacts to confidentiality, integrity, and availability, with a changed scope. The issue is rated high severity with a CVSS score of 7.1.