# Reviews Feed <= 2.14.0 - Unauthenticated Sensitive Information Exposure via Elementor Integration Feed Data

- **ID:** WPSEC-2026-0669
- **Plugin:** Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More (`reviews-feed`), https://wordpress.org/plugins/reviews-feed/
- **Affected versions:** from 2.6.3 before 2.15.0
- **Fixed in:** 2.15.0 (Update to 2.15.0 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/reviews-feed
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0669/

## Description

The Reviews Feed plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.6.3 up to, and including, 2.14.0. On sites running Elementor, the plugin attaches the complete stored feed records, including each feed's settings and its connected source records, to its front-end script on every front-end request, so they are printed in the source of any public page that displays a Reviews feed. This makes it possible for unauthenticated attackers to view the configuration of every feed and the source records behind them, including source names, identifiers and stored details, and for connected Facebook pages the stored page access token, which is encrypted with the site's keys when the OpenSSL extension is available.

## References

- https://wpsec.com/vuln/WPSEC-2026-0669/
- https://plugins.svn.wordpress.org/reviews-feed/tags/2.15.0/
- https://wordpress.org/plugins/reviews-feed/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0669/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
