Executive brief
The Reviews Feed plugin for WordPress, which displays social media reviews on websites, contains a flaw that allows outsiders to execute unauthorized commands. By posting a review containing specific WordPress codes (shortcodes) on a linked platform like Google Reviews, an attacker can force the website to execute those codes when the feed is displayed. This could lead to the exposure of private site information or unauthorized changes to how the page appears to visitors.
Technical details
The Reviews Feed plugin for WordPress (versions prior to 2.6.5) is vulnerable to arbitrary shortcode execution. The vulnerability exists in the dynamic block rendering path (Gutenberg block 'sbr/sbr-feed-block'). When the plugin fetches and caches third-party reviews (e.g., from Google), it fails to sanitize WordPress shortcodes. Because the feed is rendered via a dynamic block, the output is processed by 'do_blocks' and subsequently 'do_shortcode' during the 'the_content' filter execution. An unauthenticated attacker can plant a shortcode in a public review on a connected source; when the plugin displays this review, the shortcode is executed server-side. The impact depends on the shortcodes available on the target site, potentially leading to information disclosure or further exploitation. The classic [reviews-feed] shortcode is not affected.
Affected products
- Smash Balloon Reviews Feed < 2.6.5
Timeline
- 2026-06-29: disclosed: Publicly published by WPScan
- 2026-06-29: patched: Fixed in version 2.6.5
- 2026-07-20: advisory: NVD published date