๐Ÿ” CVE Alert

CVE-2026-10724

MEDIUM 4.8

Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

Vendor unknown
Product reviews feed
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown reviews feed

Be the first to know when new medium vulnerabilities affecting unknown reviews feed are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Reviews Feed
0 < 2.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7def5cf4-655d-424b-b1fc-eb333465434e/

Credits

Kishan Vyas WPScan