WPIntell

Source evidence

Patchstack: <=17.7 Cross Site Scripting vulnerability

WP Google Review Slider · support · 2026-06-01T14:46:00+00:00

questionsentiment
highseverity
0.65relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 13 rows with source links

23.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

10 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
megamurmulis resolved
WordPress WP Google Review Slider plugin <= 17.7 – Cross Site Scripting (XSS) vulnerability https://patchstack.com/database/wordpress/plugin/wp-google-places-review-slider/vulnerability/wordpress-wp-google-review-slider-plugin-17-7-cross-site-scripting-xss-vulnerability Required privilege: Unauthenticated Given that it was not disclosed until recently – v17.8 is likely vulnerable as well – since generic update: 17.8 Updated styling for WPv7. This would only have been an issue if an original review on Google had script tags and somehow made it past all of Google’s security and was downloaded to the plugin. So not really possible. I just pushed out V17.9 with extra output sanitation for downloaded reviews just in case.

Comments

1 shown
jgwhite33 2026-06-01T16:49:00+00:00

This would only have been an issue if an original review on Google had script tags and somehow made it past all of Google’s security and was downloaded to the plugin. So not really possible. I just pushed out V17.9 with extra output sanitation for downloaded reviews just in case.