PatchSiren

Reviews Feed CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Reviews Feed CVE published 2026-07-20

CVE-2026-10724

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block. This allows unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source. Users should review their plugin version and update if necessary. Site [truncated]