CVE-2026-100148: Rich Showcase for Google Reviews <= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API)
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].text' parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered entirely through a Google review posted for the connected business and requires no WordPress account; the plugin's default daily cron auto-imports the malicious review text, and execution triggers for every visitor on DOMContentLoaded without any further user interaction.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this without a WordPress account?
Anyone able to post a Google review for the business connected to the plugin can supply the malicious review text. Although the vulnerability is classified as authenticated subscriber-level and above, the described delivery path uses a Google review and does not require a WordPress account.
Are sites using the default configuration exposed?
Yes. The plugin's default daily cron job automatically imports review text from the connected Google Places API, including malicious review content.
When does the injected script execute?
The script executes for every visitor who accesses a page containing the injected review. It is triggered on DOMContentLoaded and requires no additional interaction from the visitor.
Which versions are affected?
All versions up to and including 7.1.3 are affected.