WordPress security by component
Site Reviews
Plugin description
Site Reviews adds review submission, rating, moderation, display, and management features for WordPress websites.
Site Reviews (site-reviews) is a WordPress plugin with 16 published CVE records in this archive. The latest tracked vulnerability was published Sep 10, 2026; the highest published CVSS base score is 9.1.
Plugin slug:
site-reviewsLatest vulnerability
CVE-2026-82925: Site Reviews permits object injection when the nonce key is predictable
Site Reviews 7.2.2 through versions before 8.3.0 deserializes request data protected by a key derived from the WordPress nonce key. If that nonce key is absent, unchanged from its sample value, or too short to remain secret, an unauthenticated attacker can compute the protection key and inject PHP objects. Site Reviews itself provides no onward gadget chain; further impact depends on other code installed on the site.
| Safe version |
|
||
|---|---|---|---|
| Sep 10, 2026 |
CVE-2026-82925
Site Reviews permits object injection when the nonce key is predictable
Site Reviews 7.2.2 through versions before 8.3.0 deserializes request data protected by a key derived from the WordPress nonce key. If that nonce key is absent, unchanged from its sample value, or too short to remain secret, an unauthenticated attacker can compute the protection key and inject PHP objects. Site Reviews itself provides no onward gadget chain; further impact depends on other code installed on the site.
|
8.3.0 |
CVE8.1
NVDPending
|
| Aug 18, 2026 |
CVE-2026-73382
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.2.0.
|
8.2.1 |
CVE7.1
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57318
Site Reviews: Sensitive information exposure
Site Reviews is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller. The published affected range is n/a through 8.0.11.
|
8.0.12 |
CVE6.5
NVDPending
|
| Mar 19, 2025 |
CVE-2025-1232
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Dec 09, 2024 |
CVE-2023-49832
Site Reviews: A security weakness
Site Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 09, 2024 |
CVE-2023-27625
Site Reviews: A security weakness
Site Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 29, 2024 |
CVE-2024-3050
Site Reviews: A security weakness
Site Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVDPending
|
| Mar 19, 2024 |
CVE-2024-29095
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 13, 2024 |
CVE-2024-2293
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 07, 2023 |
CVE-2022-46801
Site Reviews: A security weakness
Site Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.1
NVD9.8
|
| Jun 22, 2023 |
CVE-2023-27629
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 22, 2023 |
CVE-2023-27612
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| May 02, 2023 |
CVE-2023-1525
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jan 03, 2022 |
CVE-2021-24973
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Sep 06, 2021 |
CVE-2021-24603
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Jun 26, 2018 |
CVE-2018-0603
Site Reviews: Cross-site scripting
Site Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|