CVE-2026-10724
Received Received - Intake

Arbitrary Shortcode Execution in Reviews Feed WordPress Plugin

Vulnerability report for CVE-2026-10724, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder the_reviews_feed to 2.6.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Reviews Feed WordPress plugin before version 2.6.5. It allows unauthenticated attackers to execute arbitrary WordPress shortcodes by injecting them into third-party review content. The plugin fails to neutralize these shortcodes before rendering them through its dynamic block, enabling code execution on pages displaying the feed.

Detection Guidance

Check if the Reviews Feed WordPress plugin version is 2.6.5 or below. Inspect pages using the Reviews Feed block for unexpected shortcode execution in third-party reviews.

Impact Analysis

An attacker could exploit this to run malicious shortcodes on your website, potentially leading to unauthorized actions, data theft, or defacement. Since no authentication is required, any visitor could trigger the vulnerability if they can submit a review with a shortcode.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if exploited to access or expose sensitive data. Unauthorized shortcode execution may allow attackers to retrieve user information or manipulate site content, violating data protection requirements.

Mitigation Strategies

Update the Reviews Feed plugin to version 2.6.5 or higher immediately. Remove any suspicious reviews containing shortcodes from connected sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10724. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart