Reviews Feed
cpe:2.3:a:smashballoon:reviews_feed:*:*:*:*:wordpress:*:*
- < 2.6.5
A vulnerability exists in the Reviews Feed WordPress plugin in versions prior to 2.6.5. The issue arises because the plugin fails to properly sanitize WordPress shortcodes in third-party review content before displaying it through its dynamic block. This oversight allows unauthenticated attackers to execute arbitrary shortcodes on pages that showcase the feed by inserting a shortcode into a review on the connected source.
Exploitation of this vulnerability allows for the execution of arbitrary WordPress shortcodes on the affected site, with the executed shortcode's impact depending on its function and the context in which it is used.
To reproduce this vulnerability, first ensure that the Reviews Feed WordPress plugin version 2.6.0 is active. Connect the plugin to a Google reviews feed for a business where public reviews can be posted. Display the feed on a published page using the Reviews Feed block. As an unauthenticated user, post a public Google review containing a WordPress shortcode, such as a gallery shortcode, onto the business page. Once the review is fetched and cached by the plugin, load the published page that renders the feed. The embedded shortcode will be executed server-side, replacing the shortcode text with the corresponding rendered output, such as gallery markup.
Users are advised to update the Reviews Feed WordPress plugin to version 2.6.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.