Impact
The Rich Shortcodes for Google Reviews plugin allows unauthenticated attackers to store malicious script code in the contents of a Google Review. The plugin fails to properly sanitize input or escape output, so an injected script is persisted and executed whenever any user loads a page that displays the review. The vulnerability is a classic Stored XSS, which can lead to theft of session cookies, defacement, phishing, or other client‑side compromise.
Affected Systems
The affected product is the widgetpack Rich Showcase for Google Reviews plugin for WordPress, in all releases up to and including version 6.8. The vulnerability was partially mitigated in version 6.6.2, but full remediation is achieved only in releases beyond 6.8. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.2 indicates a high risk to confidentiality, integrity, or availability of affected sites. The EPSS score of less than 1% suggests that exploitation may be rare or opportunistic, and the vulnerability is not recorded in CISA’s KEV catalog. Attackers can exploit the flaw by submitting a crafted Google Review which will be stored and later rendered to visitors, making the attack vector a user‑generated content path that does not require authentication.
OpenCVE Enrichment