CVE-2026-73382

HIGH TTE 44d Pub 18/08 Upd 02/10

Overview

This vulnerability is a Stored Cross-site Scripting (XSS) flaw caused by improper neutralization of user-supplied input during web page generation. The root cause lies in the failure of the Site Reviews plugin to sanitize or encode input fields before rendering them in the HTML output. The affected component is the Gemini Labs Site Reviews plugin, specifically versions up to and including 8.2.0, where user content is embedded without adequate filtering.

Vulnerability Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0.

Impact

An unauthenticated attacker can inject persistent malicious scripts that execute in the browsers of users who visit the affected review pages. This enables theft of session tokens, manipulation of page content, or redirection to malicious sites. Because the payload is stored, all visitors to the compromised pages are exposed, potentially leading to widespread data compromise or user account hijacking. The attack requires only user interaction in viewing the infected page and does not require prior authentication or elevated privileges.

Solution

Users should upgrade the Gemini Labs Site Reviews plugin to version 8.2.1 or later, where input sanitization and output encoding have been implemented to mitigate this XSS vulnerability. Detailed patch instructions and advisories are available at Patchstack’s database entry for this vulnerability: https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-8-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve. No alternative workarounds are documented; applying the update is mandatory to remediate the issue.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest HIGH
Sightings Extensive activity

Threat Feed

3 events
2026-10-03
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-10-02
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: geminilabs, product: site_reviews

Detected as Exploited in the Wild (102 sightings)

Active exploitation confirmed with 102 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Cross-Site Scripting
100% xss

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-63 Cross-Site Scripting (XSS)
79%
High Very High
CAPEC-588 DOM-Based XSS
78%
High Very High
CAPEC-592 Stored XSS
78%
High Very High
CAPEC-591 Reflected XSS
78%
High Very High
CAPEC-209 XSS Using MIME Type Mismatch
73%
— Medium

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (2)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-73382
patchstack.com
GitHub CVE vdb-entry
https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-8-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve