Urgent: Unauthenticated XSS Threat in Rich Shortcodes for Google Reviews Plugin (CVE-2025-12499)
Overview A critical Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2025-12499, has been discovered in the Rich Shortcodes for Google Reviews plugin for WordPress. This vulnerability affects all versions up to and including 6.8. It allows unauthenticated attackers to inject malicious JavaScript code into pages through manipulated Google review content, potentially compromising user accounts and … Read more