WordPress security by component
Rich Showcase for Google Reviews
Plugin description
Rich Showcase for Google Reviews is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.1.
Plugin slug:
widget-google-reviewsLatest vulnerability
CVE-2026-15739: Google Reviews pagination shortcode attribute permits stored XSS
Rich Showcase for Google Reviews through 6.9.9 lets a Contributor store an attacker-controlled pagination value in the [grw] shortcode. Feed_Old::get_feed() carries the attribute into the feed options, and View::render_grid() or grw_place_reviews() inserts it directly as the second argument of an inline onclick handler. HTML attribute encoding at the earlier shortcode step does not make the value safe for this JavaScript context, so a crafted stored value can execute when a visitor uses the rendered reviews control.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-15739
Google Reviews pagination shortcode attribute permits stored XSS
Rich Showcase for Google Reviews through 6.9.9 lets a Contributor store an attacker-controlled pagination value in the [grw] shortcode. Feed_Old::get_feed() carries the attribute into the feed options, and View::render_grid() or grw_place_reviews() inserts it directly as the second argument of an inline onclick handler. HTML attribute encoding at the earlier shortcode step does not make the value safe for this JavaScript context, so a crafted stored value can execute when a visitor uses the rendered reviews control.
|
6.9.10 |
CVE6.4
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32360
Rich Showcase for Google Reviews: Cross-site scripting
Rich Showcase for Google Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 15, 2023 |
CVE-2022-44580
Widget Google Reviews: SQL injection
Widget Google Reviews is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.1
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-45369
Widget Google Reviews: A security weakness
Widget Google Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|