PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10724 Reviews Feed CVE debrief

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block. This allows unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source. Users should review their plugin version and update if necessary. Site administrators and security teams should review the plugin version and update if necessary to prevent exploitation.

Vendor
Reviews Feed
Product
WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-20
Advisory published
2026-07-20
Advisory updated
2026-07-20

Who should care

Users of the Reviews Feed WordPress plugin, especially those who allow third-party reviews on their sites, should be aware of this vulnerability and take steps to protect their sites. Site administrators and security teams should review the plugin version and update if necessary to prevent exploitation. Those responsible for managing WordPress plugins and ensuring site security should prioritize updating the plugin.

Technical summary

The Reviews Feed WordPress plugin before 2.6.5 does not properly sanitize third-party review content, allowing attackers to inject and execute arbitrary WordPress shortcodes. This can lead to various security issues, including code execution, data breaches, or site defacement. The plugin's dynamic block feature is particularly vulnerable to this type of attack. Users should review their plugin version and update if necessary to prevent exploitation.

Defensive priority

High with Urgency for Public-Facing Sites and Those with Third-Party Reviews Enabled

Recommended defensive actions

  • Update the Reviews Feed WordPress plugin to version 2.6.5 or later
  • Regularly monitor and review third-party review content on your site
  • Implement additional security measures, such as input validation and output encoding
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-20T07:16:34.340Z and has not been modified since then. The NVD entry is currently Received. There may be additional details in the official CVE record or NVD entry that can help with verification and mitigation. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T07:16:34.340Z and has not been modified since then.