The issue in the Rich Reviews plugin is being actively exploited.
Source: Threadpost