CVE Database /
CVE-2026-11591
CVE · Medium
CVE-2026-11591 — Widgets for Google Reviews [wp-reviews-plugin-for-google] < 13.3.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11591
|
Widgets for Google Reviews [wp-reviews-plugin-for-google] < 13.3.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.4
|
< 13.3.1
|
13.3.1 |
2026-07-10 |
—
|
CVE-2026-11591
The Widgets for Google Reviews plugin for WordPress contains a vulnerability in its admin settings input handling, allowing attackers with editor-level permissions or higher to inject malicious code into certain pages that will execute when accessed by users. This issue is present in all versions up to and including 13.3 and only affects multi-site installations where unfiltered HTML has been disabled. The flaw arises from inadequate sanitization and output protection mechanisms within the plugin's code.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings