CVE-2026-13015

MEDIUM

WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-13015. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-13015, a Reflected Cross-Site Scripting (XSS) vulnerability in the Wp Google Places Review Slider WordPress plugin (versions up to and including 18.1). The code includes metadata and a placeholder structure but lacks actual exploit implementation.

Description

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-13015_the_google_places.py

This repository contains an auto-generated stub module for CVE-2026-13015, a Reflected Cross-Site Scripting (XSS) vulnerability in the Wp Google Places Review Slider WordPress plugin (versions up to and including 18.1). The code includes metadata and a placeholder structure but lacks actual exploit implementation.

Classification
Stub 99%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: Wp Google Places Review Slider plugin for WordPress (versions <= 18.1)
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and accessible via HTTP/HTTPS · Attacker must craft a malicious URL with the 'place' parameter to trigger the XSS
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
jgwhite33/WP Google Review Slider < 18.1
Published Jul 01, 2026
Tracked Since Jul 01, 2026