Cross-site Scripting Vulnerability in Rich Showcase for Google Reviews Widget by Richplugins
CVE-2026-32360
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 March 2026
What is CVE-2026-32360?
The Rich Showcase for Google Reviews widget by Richplugins has a vulnerability that allows for stored Cross-site Scripting (XSS) attacks. This issue arises due to improper neutralization of input during web page generation, potentially enabling attackers to inject malicious scripts into user pages. Affected versions include all prior to 6.9.4.3, making it crucial for users to update to mitigate risks associated with this vulnerability.
Affected Version(s)
Rich Showcase for Google Reviews 0 <= 6.9.4.3