CVE-2026-92412: Unknown Five Star Restaurant Reviews

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.

Affected products

  • Unknown Five Star Restaurant Reviews: before 2.3.14 (fixed in 2.3.14)

Published 2026-10-01. Last modified 2026-10-01.