CVE-2023-6884: Plugin for Google Reviews <= 3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'placeid' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6884?
CVE-2023-6884 is classified as a high severity vulnerability.
How do I fix CVE-2023-6884?
To fix CVE-2023-6884, you should update the Richplugins Plugin for Google Reviews to version 3.2 or later.
What causes the vulnerability CVE-2023-6884?
CVE-2023-6884 is caused by insufficient input sanitization and output escaping on the 'place_id' attribute in the plugin's shortcode.
Who is affected by CVE-2023-6884?
CVE-2023-6884 affects all authenticated users with contributor level permissions on WordPress sites using the plugin version up to 3.1.
What type of vulnerability is CVE-2023-6884?
CVE-2023-6884 is a stored cross-site scripting (XSS) vulnerability.