CVE-2025-1232: Geminilabs Site Reviews
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks
Affected products
- Geminilabs Site Reviews: before 7.2.5 (fixed in 7.2.5)
Published 2025-03-19. Last modified 2026-06-17.