Impact
Cross‑Site Request Forgery (CSRF) in the MessageMetric Review Wave – Google Places Reviews WordPress plugin enables an attacker that can send a crafted request to the plugin’s endpoint to store malicious JavaScript in the site’s database. Once stored, the script executes whenever a user views the affected content, potentially allowing client‑side manipulation or execution of unwanted actions.
Affected Systems
MessageMetric’s Review Wave – Google Places Reviews plugin versions 1.4.7 and earlier are affected. The plugin is distributed for WordPress sites that display Google Places reviews, and the vulnerability exists from the initial release up through 1.4.7.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to send a request that bypasses missing CSRF protections, allowing the stored XSS payload to be saved in the database.
OpenCVE Enrichment
EUVD