CVE-2026-10724

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.
Configurations

No configuration.

History

20 Jul 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-345

20 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 07:16

Updated : 2026-07-21 18:51


NVD link : CVE-2026-10724

Mitre link : CVE-2026-10724

CVE.ORG link : CVE-2026-10724


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity