Impact
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to stored cross‑site scripting caused by insufficient sanitization of the 'reviews[].text' field. An attacker can inject malicious browser scripts that are executed automatically when any user loads a page containing a rendered review. This client‑side code execution can lead to session hijacking, credential theft, defacement, or phishing attacks on site visitors.
Affected Systems
The vulnerability affects the Widgetpack Rich Showcase for Google Reviews WordPress plugin; all releases through and including version 7.1.3 are impacted. No specific patch version is listed in the input, so any installation of these or earlier versions is susceptible.
Risk and Exploitability
The CVSS score is 6.4, indicating moderate severity, and the EPSS information is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated WordPress user with subscriber‑level or higher access to add a review; the plugin’s daily cron automatically imports such reviews, and the injected script executes on DOMContentLoaded for every visitor without further interaction. These conditions mean that while server‑side code execution is not possible, the risk of widespread client‑side impact remains substantial for sites that have not patched the plugin.
OpenCVE Enrichment