plugin

Social Testimonials And Reviews Widget Vulnerabilities

10 known security issues reported for the Social Testimonials And Reviews Widget WordPress plugin. Most recent disclosed Oct 22, 2025.

1 high 4 medium

Running Social Testimonials And Reviews Widget on your site? Check whether your installed version is affected.

Scan your site free

Reviews Widgets for Google &amp; 45+ platforms by Repuso [social-testimonials-and-reviews-widget] <= 5.29 (unfixed)

unknown

[en] Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 5.29.

Affected:
up to 5.29
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-62071 on NVD →

Social proof testimonials and reviews by Repuso <= 5.29 - Missing Authorization

medium

The Reviews Widgets for Google & 45+ platforms by Repuso plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in all versions up to, and including, 5.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an...

CVSS:
4.3
Affected:
up to 5.29
Fixed in:
5.30
Disclosed:
Oct 16, 2025

CVE-2025-62071 on NVD →

Social proof testimonials and reviews by Repuso <= 5.21 - Missing Authorization

medium

The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized...

CVSS:
4.3
Affected:
up to 5.21
Fixed in:
5.22
Disclosed:
Apr 1, 2025

CVE-2025-31886 on NVD →

Reviews Widgets for Google &amp; 45+ platforms by Repuso [social-testimonials-and-reviews-widget] < 5.22

unknown

[en] Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social proof testimonials and reviews by Repuso: from n/a through 5.21.

Affected:
up to 5.22
Fixed in:
5.22
Disclosed:
Apr 1, 2025

CVE-2025-31886 on NVD →

Reviews Widgets for Google &amp; 45+ platforms by Repuso [social-testimonials-and-reviews-widget] < 5.21

unknown

[en] The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions up to, and including, 5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...

Affected:
up to 5.21
Fixed in:
5.21
Disclosed:
Jan 15, 2025

CVE-2024-13351 on NVD →

Social proof testimonials and reviews by Repuso <= 5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

high

The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions up to, and including, 5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

CVSS:
7.2
Affected:
up to 5.20
Fixed in:
5.21
Disclosed:
Jan 14, 2025

CVE-2024-13351 on NVD →

Reviews Widgets for Google &amp; 45+ platforms by Repuso [social-testimonials-and-reviews-widget] < 5.00

unknown

[en] Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through 4.97.

Affected:
up to 5.00
Fixed in:
5.00
Disclosed:
Jan 2, 2025

CVE-2023-46196 on NVD →

Social proof testimonials and reviews by Repuso <= 4.97 - Missing Authorization

medium

The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 4.97. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
4.3
Affected:
up to 4.97
Fixed in:
5.00
Disclosed:
Oct 18, 2023

CVE-2023-46196 on NVD →

Reviews Widgets for Google &amp; 45+ platforms by Repuso [social-testimonials-and-reviews-widget] < 5.02

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Repuso Social proof testimonials and reviews by Repuso plugin <= 5.00 versions.

Affected:
up to 5.02
Fixed in:
5.02
Disclosed:
Oct 12, 2023

CVE-2023-45048 on NVD →

Social proof testimonials and reviews by Repuso <= 5.01 - Cross-Site Request Forgery

medium

The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.01. This is due to missing or incorrect nonce validation on the pagewide_widget function. This makes it possible for unauthenticated attackers to change widget setting...

CVSS:
5.4
Affected:
up to 5.01
Fixed in:
5.02
Disclosed:
Oct 3, 2023

CVE-2023-45048 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database