Impact
The Widgets for Google Reviews plugin for WordPress suffers from insufficient input sanitization and output escaping in the 'fomo-title' and 'fomo-text' parameters of its admin settings. This flaw allows an authenticated attacker who holds editor‑level or higher permissions to inject arbitrary JavaScript that will execute whenever a user loads a page containing the compromised widget. The vulnerability is identified as CWE‑79 and can be used to deface content, capture credentials, or hijack user sessions on the site.
Affected Systems
All installations of trustindex:Widgets for Google Reviews plugin versions 13.3 or earlier, including version 13.3 itself. The impact applies only to multi‑site WordPress installations or installations where the unfiltered_html capability has been disabled, affecting sites managed under a network or with that capability turned off.
Risk and Exploitability
The CVSS v3.1 score of 4.4 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector requires authenticated access with editor or higher privileges, making the threat relevant to sites with loosely controlled role permissions or insufficiently segregated user groups.
OpenCVE Enrichment