Description
The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Published: 2026-07-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Widgets for Google Reviews plugin for WordPress suffers from insufficient input sanitization and output escaping in the 'fomo-title' and 'fomo-text' parameters of its admin settings. This flaw allows an authenticated attacker who holds editor‑level or higher permissions to inject arbitrary JavaScript that will execute whenever a user loads a page containing the compromised widget. The vulnerability is identified as CWE‑79 and can be used to deface content, capture credentials, or hijack user sessions on the site.

Affected Systems

All installations of trustindex:Widgets for Google Reviews plugin versions 13.3 or earlier, including version 13.3 itself. The impact applies only to multi‑site WordPress installations or installations where the unfiltered_html capability has been disabled, affecting sites managed under a network or with that capability turned off.

Risk and Exploitability

The CVSS v3.1 score of 4.4 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector requires authenticated access with editor or higher privileges, making the threat relevant to sites with loosely controlled role permissions or insufficiently segregated user groups.

Generated by OpenCVE AI on August 1, 2026 at 11:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Widgets for Google Reviews plugin to a version newer than 13.3, if one is available, to remove the stored Super‑Administrator users have editor‑level or higher permissions, and consider restricting or removing the editor role from users who do not require it.
  • As a temporary measure, disable the unfiltered_html capability for non‑super‑administrator roles or configure the site to enforce content filtering so that any script tags entered in widget settings are removed before storage.
  • Delete any existing widget entries that contain unexpected scripts and regenerate the widget configuration from trusted sources.

Generated by OpenCVE AI on August 1, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Trustindex
Trustindex widgets For Google Reviews
Wordpress
Wordpress wordpress
Vendors & Products Trustindex
Trustindex widgets For Google Reviews
Wordpress
Wordpress wordpress

Sat, 11 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Title Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Trustindex Widgets For Google Reviews
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-13T16:12:30.040Z

Reserved: 2026-06-08T13:46:43.638Z

Link: CVE-2026-11591

cve-icon Vulnrichment

Updated: 2026-07-13T16:12:26.875Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')