Widgets for Google Reviews
wp-reviews-plugin-for-google · plugin
Known security vulnerabilities for Widgets for Google Reviews. Find out in seconds which version runs on your site with WP Lens.
5 known vulnerabilities
2 exploitable without logging in · latest Jul 11, 2026
Listed on wordpress.org · latest 14.2 · last updated Sep 24, 2026 · 1M+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 8.0
CVE-2023-48275high privilege≤ 11.0.2
WordPress Widgets for Google Reviews plugin <= 11.0.2 - Arbitrary File Upload vulnerability
- High 7.2
CVE-2025-12510unauthenticated≤ 13.2.4
Widgets for Google Reviews <= 13.2.4 - Unauthenticated Stored Cross-Site Scripting via Google Reviews
- Medium 6.4
CVE-2025-9436contributor+≤ 13.2.1
Widgets for Google Reviews <= 13.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trustindex Shortcode
- Medium 4.4
CVE-2026-11591editor+≤ 13.3
Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
- Medium 4.3
CVE-2023-3254unauthenticated · needs a click≤ 10.9
Widgets for Google Reviews <= 10.9 - Cross-Site Request Forgery to Plugin Settings Reset
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).