PT-2026-104496 · WordPress · Rich Showcase For Google Reviews

·

CVE-2026-100148

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rich Showcase for Google Reviews versions prior to 7.1.4
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with subscriber-level access or higher can inject arbitrary web scripts into pages. The malicious payload is delivered via a Google review posted for the connected business and is automatically imported by the plugin's default daily cron. The script executes for every visitor upon the DOMContentLoaded event, which is the moment when the initial HTML document has been completely loaded and parsed, without requiring further user interaction.
Recommendations Update the plugin to version 7.1.4 or later. Restrict the use of the reviews[].text parameter until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100148

Affected Products

Rich Showcase For Google Reviews