CVE-2026-11591: Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11591?
CVE-2026-11591 has a medium severity rating of 4.4.
How do I fix CVE-2026-11591?
To fix CVE-2026-11591, update the Widgets for Google Reviews plugin to a version higher than 13.3.
Who is affected by CVE-2026-11591?
Authenticated users with editor-level permissions in the Widgets for Google Reviews plugin are affected by CVE-2026-11591.
What type of vulnerability is CVE-2026-11591?
CVE-2026-11591 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What are the impacts of CVE-2026-11591?
The impacts of CVE-2026-11591 include the potential for authenticated attackers to execute scripts in the context of the user's session.