<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Ultimate Review (&lt;= 2.4.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wp-ultimate-review--2.4.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 08:34:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wp-ultimate-review--2.4.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Shortcode Execution in WP Ultimate Review</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92235/</link><pubDate>Tue, 22 Sep 2026 08:34:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92235/</guid><description>The WP Ultimate Review plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92235) that allows authenticated attackers with subscriber-level access to execute arbitrary shortcodes.</description><content:encoded><![CDATA[<p>The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to and including 2.4.2. The flaw exists because the software fails to properly validate user-supplied input before passing it to the 'do_shortcode' function. An authenticated attacker with subscriber-level permissions or higher can exploit this lack of validation to trigger arbitrary shortcode execution. This vulnerability is significant as it allows low-privileged users to perform unauthorized actions or gain access to sensitive information typically restricted by the application, depending on the available shortcodes registered within the WordPress environment. Organizations using this plugin should evaluate their use of shortcodes and upgrade to a patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated subscriber to execute arbitrary shortcodes, potentially leading to unauthorized data disclosure, privilege escalation, or unauthorized modifications within the WordPress site depending on the installed plugins and theme capabilities.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor WordPress administrative activity logs for unexpected shortcode usage by subscriber-level accounts.</li>
<li>Review the list of active plugins to identify those that register potentially sensitive or administrative shortcodes.</li>
<li>Update the WP Ultimate Review plugin to the latest version once a patch is released to remediate CVE-2026-92235.</li>
<li>Audit subscriber-level account permissions to ensure they are constrained from accessing sensitive plugin configurations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>web-application</category></item></channel></rss>