Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-92412
CVE-2026-92412
Description
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.3.14
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.