CVE-2026-73382
Overview
This vulnerability is a Stored Cross-site Scripting (XSS) flaw caused by improper neutralization of user-supplied input during web page generation. The root cause lies in the failure of the Site Reviews plugin to sanitize or encode input fields before rendering them in the HTML output. The affected component is the Gemini Labs Site Reviews plugin, specifically versions up to and including 8.2.0, where user content is embedded without adequate filtering.
Vulnerability Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0.
Impact
An unauthenticated attacker can inject persistent malicious scripts that execute in the browsers of users who visit the affected review pages. This enables theft of session tokens, manipulation of page content, or redirection to malicious sites. Because the payload is stored, all visitors to the compromised pages are exposed, potentially leading to widespread data compromise or user account hijacking. The attack requires only user interaction in viewing the infected page and does not require prior authentication or elevated privileges.
Solution
Users should upgrade the Gemini Labs Site Reviews plugin to version 8.2.1 or later, where input sanitization and output encoding have been implemented to mitigate this XSS vulnerability. Detailed patch instructions and advisories are available at Patchstack’s database entry for this vulnerability: https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-8-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve. No alternative workarounds are documented; applying the update is mandatory to remediate the issue.