CVE-2026-4161Disclosure

MEDIUMCVSS 4.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-21); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-21: 3Mentions · 2026-05-20: 2Active Exploitation · 2026-05-20: 2Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-03-21: 303-2105-20
Signal classification3 categories
Disclosure
240.0%
Active Exploitation
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-213
Disclosure2Patch1
2026-05-202
Active Exploitation2
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4161 The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due t… https://www.cve.org/CVERecord?id=CVE-2026-4161

    Post summary

    The post announces CVE-2026-4161, a stored XSS flaw in the RevuKangaroo Review Map WordPress plugin for all versions up to 1.7.

    0001060
    56.8K followersView on X
  • Carlos Fynn@fynn_JourX
    Active Exploitation

    Microsoft Authenticator Token Theft Risk (CVE-2026-4161… is the kind of management-plane bug defenders should move on fast. It combines active exploitation with security exposure and auth bypass risk in FortiClient EMS. When endpoint management infrastructure is expose…

    Post summary

    The text indicates that CVE‑2026-4161 is actively exploited, creating an authentication bypass in FortiClient EMS, but it lacks details on the exploit mechanism or mitigation.

    0000078
    87 followersView on X
  • Lucas@lucasverdan
    Active Exploitation

    Microsoft Authenticator Token Theft Risk (CVE-2026-4161… is already being exploited, and Fortinet says the FortiClient EMS flaw carries security exposure and auth bypass risk. If you run 7.4.5 or 7.4.6, treat it as exposed management-plane risk and hotfix now.

    Post summary

    The post claims CVE‑2026‑4161 is currently being exploited and urges a hotfix for specific FortiClient versions, but provides no proof of concept or detailed technical information.

    0000086
    308 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, administradores WordPress! A vulnerabilidade de Stored XSS no plugin Review Map by RevuKangaroo afeta instalações multi-site ⚠️. Atualize agora para proteger seu site contra injeções maliciosas! Saiba mais: https://www.tenable.com/cve/CVE-2026-4161 #CyberSecurity #WordPress #XSS

    Post summary

    The post alerts administrators to a stored XSS flaw in the Review Map plugin for WordPress multisite and urges them to update their installs to mitigate the risk, without providing a PoC or detailed exploit.

    0000032
    259 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4161 Stored XSS in Review Map WordPress Plugin via Unfiltered Settings Input https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4161

    Post summary

    The post announces a Stored XSS vulnerability (CVE‑2026‑4161) in the Review Map WordPress plugin, triggered by unfiltered settings input, without any exploitation or patch details.

    0000033
    4.0K followersView on X

Explore more