CVE-2026-10724 PUBLISHED

Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews

Assigner: WPScan
Reserved: 03.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

Product Status

Vendor Unknown
Product Reviews Feed
Versions Default: unaffected
  • affected from 0 to 2.6.5 (excl.)

Credits

  • Kishan Vyas finder
  • WPScan coordinator

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE