Junglewise Threat Intelligence

CVE-2026-13015: WP Google Review Slider Reflected XSS in place parameter

CVE-2026-13015 · Severity: medium · CVSS 6.1 · Published 2026-07-01

Vendors: Jgwhite33.

Executive brief

The WP Google Review Slider plugin for WordPress, which is used to display Google reviews on websites, contains a security flaw that allows attackers to execute malicious scripts in a user's browser. This occurs when a user is tricked into clicking a specially crafted link, potentially leading to unauthorized actions or data theft within the context of the affected site. The vulnerability impacts all versions of the plugin up to and including 18.1.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the WP Google Review Slider plugin for WordPress within the 'admin/partials/googlecrawl_dfs.php' file. The root cause is the improper handling of the 'place' GET parameter, which is URL-decoded and processed with stripslashes() before being echoed directly into an HTML value attribute without appropriate escaping (e.g., via esc_attr()). An unauthenticated attacker can exploit this by crafting a malicious URL and social engineering a user into clicking it. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session. The issue is present in versions up to and including 18.1.

Affected products

  • jgwhite33 WP Google Review Slider up to, and including, 18.1

Timeline

  • 2026-07-01: advisory: NVD publication date

References

Related threats