The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding untrusted vicinity content inside those tags. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding untrusted vicinity content inside those tags. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-27T14:34:17.895Z
Reserved: 2026-02-12T02:22:14.129Z
Link: CVE-2026-2388
Updated: 2026-08-27T13:53:05.734Z
Status : Deferred
Published: 2026-08-26T10:16:40.447
Modified: 2026-08-27T17:17:49.727
Link: CVE-2026-2388
No data.
OpenCVE Enrichment
Updated: 2026-08-26T10:30:04Z