Executive brief
The CBX 5 Star Rating & Review plugin for WordPress, which allows site owners to display customer reviews, contains a security flaw that could allow an attacker to run malicious scripts in a site administrator's browser. To exploit this, an attacker would typically trick an administrator into clicking a specially crafted link. If successful, this could allow the attacker to perform unauthorized actions on the website or steal sensitive session information.
Technical details
The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'page' parameter. This vulnerability exists in versions up to and including 1.0.7. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a script and tricking a privileged user, such as an administrator, into clicking it. The script then executes within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. The issue appears to be addressed in version 1.0.8.
Affected products
- Codeboxr CBX 5 Star Rating & Review Up to, and including, 1.0.7
Timeline
- 2026-05-22: disclosed: Initial publication of the CVE record
- 2026-05-22: advisory: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/templates/admin/admin-rating-review-rating-avg-logs.php
- https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.7/templates/admin/admin-rating-review-review-logs.php
- https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.8/templates/admin/admin-rating-review-rating-avg-logs.php
- https://plugins.trac.wordpress.org/browser/cbxscratingreview/tags/1.0.8/templates/admin/admin-rating-review-review-logs.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9ee11e19-21a6-45df-a118-f6dec3b55bc1?source=cve