Executive brief
The Rich Showcase for Google Reviews plugin for WordPress, which is used to display customer reviews on websites, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts will execute, potentially leading to unauthorized actions or data theft.
Technical details
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'pagination' shortcode attribute. This vulnerability exists in all versions up to and including 6.9.9. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a page via a shortcode. These scripts will execute in the context of any user's browser who visits the affected page. The issue was addressed in subsequent updates following version 6.9.9.
Affected products
- widgetpack Rich Showcase for Google Reviews up to, and including, 6.9.9
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-feed-old.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-feed-shortcode.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-view.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.7/includes/class-view.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-feed-old.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-feed-shortcode.php
- https://plugins.trac.wordpress.org/browser/widget-google-reviews/tags/6.9.8/includes/class-view.php