WordPress Plugin Vulnerabilities

Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews

Description

The plugin does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

Proof of Concept

Affects Plugins

Fixed in 2.6.5

References

Classification

Type
CONTENT INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
Kishan Vyas
Submitter
Kishan Vyas
Verified
Yes

Timeline

Publicly Published
2026-06-29 (about 22 days ago)
Added
2026-06-29 (about 21 days ago)
Last Updated
2026-06-29 (about 21 days ago)

Other