Known CVE
Site Reviews < 7.2.5 - Unauthenticated Stored XSS
Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.
CVE-2025-1232
High2025CVSS 8.8CWE-79
cve2025 · wordpress · wp · wp-plugin · site-reviews · xss · stored
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website