cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwidget-google-reviews widget-google-reviews

Direction: descending
Jan 10, 2026

Plugin for Google Reviews # CVE-2025-12499

CVE, Research URL

CVE-2025-12499

Date
Dec 06, 2025
Research Description
The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially patched in version 6.6.2.
Affected versions
max 6.8.1.
Status
vulnerable
Jun 07, 2024

Plugin for Google Reviews # CVE-2023-6884

CVE, Research URL

CVE-2023-6884

Date
Feb 06, 2024
Research Description
This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.2.
Status
vulnerable

Plugin for Google Reviews # CVE-2022-45369

CVE, Research URL

CVE-2022-45369

Date
Nov 19, 2022
Research Description
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
Affected versions
max 2.2.3.
Status
vulnerable

Plugin for Google Reviews # CVE-2022-44580

CVE, Research URL

CVE-2022-44580

Date
Mar 15, 2023
Research Description
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
Affected versions
max 2.2.4.
Status
vulnerable