CVE-2026-73382: WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Site Reviews pluginto a version that resolves this vulnerability.Fixed in 8.2.1
Event History
Frequently Asked Questions
Which sites are exposed, and does exploitation require an account?
Any WordPress site using the Site Reviews plugin version 8.2.0 or earlier is identified as affected. The issue is described as unauthenticated, so an attacker does not need a WordPress account or other privileges.
What can be done while an update is not immediately possible?
The supplied information does not state whether the vulnerable behavior is enabled in a default configuration, which input or feature triggers it, or whether a workaround is available. If patching cannot be performed immediately, assess exposure to public, attacker-controlled input associated with the plugin and monitor for suspicious injected script content.