CVE-2026-73382: WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0.
Other sources
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Site Reviews pluginto a version that resolves this vulnerability.Fixed in 8.2.1
Event History
Frequently Asked Questions
Which sites are exposed, and does exploitation require an account?
Any WordPress site using the Site Reviews plugin version 8.2.0 or earlier is identified as affected. The issue is described as unauthenticated, so an attacker does not need a WordPress account or other privileges.
What can be done while an update is not immediately possible?
The supplied information does not state whether the vulnerable behavior is enabled in a default configuration, which input or feature triggers it, or whether a workaround is available. If patching cannot be performed immediately, assess exposure to public, attacker-controlled input associated with the plugin and monitor for suspicious injected script content.