SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-10724

MEDIUM · CVSS 4.8 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Reviews Feed WordPress plugin prior to version 2.6.5 is vulnerable to arbitrary shortcode execution due to inadequate sanitization of third-party review content. This flaw allows unauthenticated attackers to inject malicious shortcodes into pages displaying the review feed, potentially leading to unauthorized actions on the site. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-10724
Severity
MEDIUM
CVSS
4.8
EPSS
0.09%
WordPress

Original NVD Description

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.