Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute
medium
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 6.9.9
- Fixed in:
- 6.9.10
- Disclosed:
- Jul 23, 2026
CVE-2026-15739 on NVD →
Rich Showcase for Google Reviews <= 6.9.4.3 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.9.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scr...
- CVSS:
- 4.4
- Affected:
- up to 6.9.4.3
- Fixed in:
- 6.9.4.4
- Disclosed:
- Feb 15, 2026
CVE-2026-32360 on NVD →
Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google Review
high
The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 7.2
- Affected:
- up to 6.8
- Fixed in:
- 6.8.1
- Disclosed:
- Dec 5, 2025
CVE-2025-12499 on NVD →
Plugin for Google Reviews <= 3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
medium
This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above permissi...
- CVSS:
- 6.4
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- Jan 12, 2024
CVE-2023-6884 on NVD →
Plugin for Google Reviews <= 2.2.3 - Authenticated (Subscriber+) SQL Injection
high
The Plugin for Google Reviews plugin for WordPress is vulnerable to generic SQL Injection via the $place_id value in versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 8.8
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Feb 8, 2023
CVE-2022-44580 on NVD →
Plugin for Google Reviews <= 2.2.2 - Cross-Site Request Forgery
high
The Plugin for Google Reviews for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to create widgets, via forged request granted they can trick a...
- CVSS:
- 8.8
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Nov 16, 2022
Plugin for Google Reviews <= 2.2.2 - Missing Authorization
medium
The Plugin for Google Reviews for WordPress is vulnerable to authorization bypass due to a missing capability check on the save function in versions up to, and including, 2.2.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create widgets.
- CVSS:
- 5.4
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Nov 16, 2022
CVE-2022-45369 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database