MinorCritical vulnerability
CVE-2026-92412 (CVSS 7.1)
NVD · officialPublished Oct 1, 2026Risk 23/100
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
Technical details
CVSS
7.1
AV:NetworkAC:LowPR:NoneUI:RequiredC:LowI:LowA:Low
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source