Reviews Feed <= 2.14.0 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Feed Data
- ID
- WPSEC-2026-0668
- Plugin
- Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More (reviews-feed)
- Affected
- from 2.6.3 before 2.15.0
- Remediation
- Update to 2.15.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Reviews Feed on WPSec AttackSurface
- Fix released
- Published
Description
The Reviews Feed plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.6.3 up to, and including, 2.14.0. The feed block passes the complete stored feed records, including each feed's settings and its connected source records, to the block editor, although the block's feed picker uses only each feed's ID and name. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the configuration of every feed and the source records behind them by opening the post editor, including source names, identifiers and stored details, and for connected Facebook pages the stored page access token, which is encrypted with the site's keys when the OpenSSL extension is available.
References
- https://wpsec.com/vuln/WPSEC-2026-0668/
- https://plugins.svn.wordpress.org/reviews-feed/tags/2.15.0/
- https://wordpress.org/plugins/reviews-feed/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS