PT-2026-104496 · WordPress · Rich Showcase For Google Reviews
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rich Showcase for Google Reviews versions prior to 7.1.4
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with subscriber-level access or higher can inject arbitrary web scripts into pages. The malicious payload is delivered via a Google review posted for the connected business and is automatically imported by the plugin's default daily cron. The script executes for every visitor upon the DOMContentLoaded event, which is the moment when the initial HTML document has been completely loaded and parsed, without requiring further user interaction.
Recommendations
Update the plugin to version 7.1.4 or later.
Restrict the use of the
reviews[].text parameter until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rich Showcase For Google Reviews