PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66428 jgwhite33 CVE debrief

A Cross Site Request Forgery (CSRF) vulnerability was found in WP Google Review Slider plugin versions up to 18.4. The vulnerability allows unauthenticated attackers to perform actions on behalf of users, potentially leading to unintended actions being performed. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.3, indicating a Medium severity level. The vulnerability is caused by a lack of proper validation and sanitization of user requests, allowing an attacker to trick users into performing unintended actions. Users of WP Google Review Slider plugin versions up to 18.4 should be aware of this vulnerability and take necessary actions to protect their installations.

Vendor
jgwhite33
Product
WP Google Review Slider
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of WP Google Review Slider plugin versions up to 18.4, administrators, security teams, and operators who manage and maintain the plugin should be aware of this vulnerability and take necessary actions to protect their installations.

Technical summary

The vulnerability is caused by a lack of proper validation and sanitization of user requests, allowing an attacker to trick users into performing unintended actions. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N. The vulnerability affects WP Google Review Slider plugin versions up to 18.4 and has a Medium severity level.

Defensive priority

Medium priority should be given to patching this vulnerability, as it allows for Cross Site Request Forgery (CSRF) attacks. However, the actual priority may vary depending on the specific use case and environment.

Recommended defensive actions

  • Apply the latest patch or update to version 18.5 or later
  • Implement additional security measures such as validating and sanitizing user requests
  • Monitor for suspicious activity and implement compensating controls if necessary
  • Review and update incident response plans to address potential CSRF attacks
  • Conduct a thorough review of the plugin's configuration and security settings

Evidence notes

The CVE record was published on 2026-07-27T15:17:10.780Z and last modified on 2026-07-27T17:46:02.447Z. The NVD entry is currently Deferred. The vulnerability details are based on the information available from the CVE record and NVD entry. However, the scope and impact of the vulnerability may not be fully understood due to limited information. Defenders should verify the affected scope and severity with the vendor and consider implementing compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:10.780Z and has not been modified since then. The NVD entry is currently Deferred.