← WordPress Vulnerabilities
WordPress security by component

Rich Showcase for Google Reviews

Rich Showcase for Google Reviews is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.1.

Plugin slug: widget-google-reviews

CVE-2026-15739: Google Reviews pagination shortcode attribute permits stored XSS

Rich Showcase for Google Reviews through 6.9.9 lets a Contributor store an attacker-controlled pagination value in the [grw] shortcode. Feed_Old::get_feed() carries the attribute into the feed options, and View::render_grid() or grw_place_reviews() inserts it directly as the second argument of an inline onclick handler. HTML attribute encoding at the earlier shortcode step does not make the value safe for this JavaScript context, so a crafted stored value can execute when a visitor uses the rendered reviews control.

PublishedJul 24, 2026
Known safe version6.9.10
Safe version
Jul 24, 2026 CVE-2026-15739
Google Reviews pagination shortcode attribute permits stored XSS
Rich Showcase for Google Reviews through 6.9.9 lets a Contributor store an attacker-controlled pagination value in the [grw] shortcode. Feed_Old::get_feed() carries the attribute into the feed options, and View::render_grid() or grw_place_reviews() inserts it directly as the second argument of an inline onclick handler. HTML attribute encoding at the earlier shortcode step does not make the value safe for this JavaScript context, so a crafted stored value can execute when a visitor uses the rendered reviews control.
6.9.10
CVE6.4
NVDPending
Mar 13, 2026 CVE-2026-32360
Rich Showcase for Google Reviews: Cross-site scripting
Rich Showcase for Google Reviews is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Mar 15, 2023 CVE-2022-44580
Widget Google Reviews: SQL injection
Widget Google Reviews is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.1
NVD8.8
Nov 18, 2022 CVE-2022-45369
Widget Google Reviews: A security weakness
Widget Google Reviews is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3