CVE-2026-92412: Unknown Five Star Restaurant Reviews
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
Affected products
- Unknown Five Star Restaurant Reviews: before 2.3.14 (fixed in 2.3.14)
Published 2026-10-01. Last modified 2026-10-01.