WordPress security by component
Five Star Restaurant Reviews
Five Star Restaurant Reviews (five-star-restaurant-reviews) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
five-star-restaurant-reviewsLatest vulnerability
CVE-2026-92412: Five Star Restaurant Reviews: Unauthenticated reflected XSS in HTML output
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.3.14.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-92412
Five Star Restaurant Reviews: Unauthenticated reflected XSS in HTML output
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.3.14.
|
2.3.14 |
CVEPending
NVDPending
|