Medium severity4.8NVD Advisory· Published Jan 28, 2022· Updated Jun 17, 2026
CVE-2022-23979
CVE-2022-23979
Description
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:etoilewebdesign:ultimate_reviews:*:*:*:*:*:wordpress:*:*Range: <=3.0.15
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=3.0.15
Patches
Vulnerability mechanics
References
2- patchstack.com/database/vulnerability/ultimate-reviews/wordpress-ultimate-reviews-plugin-3-0-15-authenticated-stored-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
- wordpress.org/plugins/ultimate-reviews/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.