Ultimate Reviews < 2.1.33 - PHP Object Injection
Summary
| CVE | CVE-2020-36726 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-07 02:15:12 UTC |
| Updated | 2026-04-08 19:17:36 UTC |
| Description | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.010670000 probability, percentile 0.776920000 (date 2026-04-09)
Problem Types: CWE-502 | CWE-502 CWE-502 Deserialization of Untrusted Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Etoilewebdesign | Ultimate Reviews | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rustaurius | Ultimate Reviews | affected 2.1.33 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ultimate Reviews < 2.1.33 - PHP Object Injection | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| WordPress Ultimate Reviews plugin fixed insecure deserialization vulnerability. – NinTechNet | af854a3a-2127-422b-91ae-364da2661108 | blog.nintechnet.com | Exploit |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Release Notes |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jerome Bruandet (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2020-11-10T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.