The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6. This vulnerability allows authenticated attackers with administrator-level access to append additional SQL queries into existing queries, potentially leading to the extraction of sensitive information from the database. Administrators and [truncated]
CVE-2026-39451 is a MEDIUM severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WP Google Review Slider plugin versions <= 18.0. The vulnerability has a CVSS score of 6.3 and was published on {cvePublishedAt}.
CVE-2019-25745 is a time-based blind SQL injection vulnerability in WordPress Plugin Google Review Slider 6.1. The vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques.