Retour à la veille

CVE-2026-10724

Publié : 20 juillet 2026
Modifié : 20 juillet 2026
Lien officiel NVD
Score CVSS
4.8
MEDIUM

Description détaillée

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the connected source.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Références et Patchs