CyberRota Analysis
AI-GeneratedThe Reviews Feed WordPress plugin prior to version 2.6.5 is vulnerable to arbitrary shortcode execution due to inadequate sanitization of third-party review content. This flaw allows unauthenticated attackers to inject malicious shortcodes into pages displaying the review feed, potentially leading to unauthorized actions on the site. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.