Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 07 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jul 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Widgetpack
Widgetpack reviews Widgets For Google, Tripadvisor, Yelp & Recommendations Wordpress Wordpress wordpress |
|
| Vendors & Products |
Widgetpack
Widgetpack reviews Widgets For Google, Tripadvisor, Yelp & Recommendations Wordpress Wordpress wordpress |
Mon, 06 Jul 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute through Feed_Old::get_feed() into the View::render() method, where it is echoed directly into the data-id HTML attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-07T14:07:04.454Z
Reserved: 2026-06-12T18:25:48.496Z
Link: CVE-2026-12154
Updated: 2026-07-07T14:07:00.535Z
Status : Deferred
Published: 2026-07-06T18:16:36.670
Modified: 2026-07-07T15:16:42.180
Link: CVE-2026-12154
No data.
OpenCVE Enrichment
Updated: 2026-08-01T18:30:05Z