Junglewise Threat Intelligence

CVE-2026-39451: WP Google Review Slider unauthenticated XSS

CVE-2026-39451 · Severity: medium · CVSS 6.3 · Published 2026-06-15

Executive brief

A vulnerability exists in the WP Google Review Slider plugin for WordPress, which is used to display Google business reviews on websites. An attacker could use this flaw to inject malicious scripts into the site, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of visitor information. This occurs when a site administrator or visitor interacts with a specially crafted link or page created by the attacker.

Technical details

The WP Google Review Slider plugin for WordPress (versions up to and including 18.0) is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into performing an action, such as clicking a malicious link or visiting a crafted page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can be used to hijack sessions or deface the website. The issue is resolved in version 18.1.

Affected products

  • WP Google Review Slider WP Google Review Slider <= 18.0

Timeline

  • 2026-04-06: disclosed: Reported by hhhai
  • 2026-06-01: patched: Version 18.1 released
  • 2026-06-15: advisory: NVD and Patchstack published advisory

References