The issue in the Rich Reviews plugin is being actively exploited.
https://threatpost.com/unpatched-bug-wordpress-xss/148656/