A reported injection into a widely used e-commerce reviews widget shows how a trusted storefront component can become a client-side risk surface.