PT-2026-25207 · Richplugins · Rich Showcase For Google Reviews

Nguyen Ba Khanh

·

Published

2026-03-13

·

Updated

2026-03-15

·

CVE-2026-32360

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Rich Showcase for Google Reviews versions through 6.9.4.3
Description A flaw exists in the Rich Showcase for Google Reviews widget that allows for Stored Cross-site Scripting (XSS). This occurs due to improper neutralization of input during web page generation. The issue allows an attacker to inject malicious scripts into web pages, potentially compromising user data or system integrity.
Recommendations Update Rich Showcase for Google Reviews to a version later than 6.9.4.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-32360

Affected Products

Rich Showcase For Google Reviews