Site Reviews WordPress plugin before 7.2.5 contains a stored cross-site scripting caused by improper sanitization and escaping of review fields, letting unauthenticated users execute malicious scripts, exploit requires no authentication.
id: CVE-2025-1232
info:
name: Site Reviews < 7.2.5 - Unauthenticated Stored XSS
author: 0x_Akok
...