Impact
Unauthenticated Cross Site Scripting has been identified in the WordPress Site Reviews plugin up to version 8.2.0, which allows an attacker to embed arbitrary script tags into pages that the plugin renders. This flaw can result in defacement, theft of user credentials stored in cookies, or the execution of malicious code in visitors’ browsers, compromising confidentiality, integrity, or availability of the website.
Affected Systems
Gemini Labs’ Site Reviews plugin for WordPress is affected. All WordPress installations that use Site Reviews version 8.2.0 or any earlier release are vulnerable, regardless of whether the site is publicly accessible or behind authentication.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. No EPSS score is available, but the flaw is not listed in CISA KEV. Because it is unauthenticated, an attacker can trigger it simply by visiting a crafted URL or submitting a malicious review, making exploitation straightforward over the web.
OpenCVE Enrichment