WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / August 26, 2026

Vulnerability in Reviews and Rating – Google Reviews — CVE-2026-2388

MediumSeverity
CVSS 6.4
0.2%Estimated exploit probability
EPSS
20,000+ sitesInstalls
Not publishedFixed in

What to do now

No fix has been published yet. Consider disabling Reviews and Rating – Google Reviews for now, or moving to an alternative.

Affected versions

  • Everything up to and including 5.10

Affected: Reviews and Rating – Google Reviews (plugin, g-business-reviews-rating)

Check: The plugin on wordpress.org / Our record for Reviews and Rating – Google Reviews

What the vulnerability is

The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This is due to the wp_display() shortcode handler, used by multiple shortcodes, allowing attacker-controlled html_tags values to define raw HTML tags and then embedding untrusted vicinity content inside those tags. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts