Review
Reviews Feed
CVE published 2026-07-20
CVE-2026-10724
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block. This allows unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source. Users should review their plugin version and update if necessary. Site [truncated]