plugin

Widget Google Reviews Vulnerabilities

7 known security issues reported for the Widget Google Reviews WordPress plugin. Most recent disclosed Jul 23, 2026.

3 high 4 medium

Running Widget Google Reviews on your site? Check whether your installed version is affected.

Scan your site free

Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute

medium

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level a...

CVSS:
6.4
Affected:
up to 6.9.9
Fixed in:
6.9.10
Disclosed:
Jul 23, 2026

CVE-2026-15739 on NVD →

Rich Showcase for Google Reviews <= 6.9.4.3 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.9.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scr...

CVSS:
4.4
Affected:
up to 6.9.4.3
Fixed in:
6.9.4.4
Disclosed:
Feb 15, 2026

CVE-2026-32360 on NVD →

Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google Review

high

The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
7.2
Affected:
up to 6.8
Fixed in:
6.8.1
Disclosed:
Dec 5, 2025

CVE-2025-12499 on NVD →

Plugin for Google Reviews <= 3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

medium

This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above permissi...

CVSS:
6.4
Affected:
up to 3.1
Fixed in:
3.2
Disclosed:
Jan 12, 2024

CVE-2023-6884 on NVD →

Plugin for Google Reviews <= 2.2.3 - Authenticated (Subscriber+) SQL Injection

high

The Plugin for Google Reviews plugin for WordPress is vulnerable to generic SQL Injection via the $place_id value in versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...

CVSS:
8.8
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Feb 8, 2023

CVE-2022-44580 on NVD →

Plugin for Google Reviews <= 2.2.2 - Cross-Site Request Forgery

high

The Plugin for Google Reviews for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to create widgets, via forged request granted they can trick a...

CVSS:
8.8
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Nov 16, 2022

Plugin for Google Reviews <= 2.2.2 - Missing Authorization

medium

The Plugin for Google Reviews for WordPress is vulnerable to authorization bypass due to a missing capability check on the save function in versions up to, and including, 2.2.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create widgets.

CVSS:
5.4
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Nov 16, 2022

CVE-2022-45369 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database