The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3. This vulnerability exists due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query, allowing authenticated attackers with administrator-level access and above to append additiona [truncated]
A Cross Site Request Forgery (CSRF) vulnerability was found in WP Google Review Slider plugin versions up to 18.4. The vulnerability allows unauthenticated attackers to perform actions on behalf of users, potentially leading to unintended actions being performed. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.3, indicating a Medium severity level. The vulnerability is cau [truncated]
CVE-2026-66427 is a SQL injection vulnerability in the WP Google Review Slider plugin for WordPress, affecting versions up to and including 18.4. The vulnerability has a CVSS score of 7.6 and is classified as HIGH severity. It requires administrator privileges to exploit, allowing attackers to inject malicious SQL code. Administrators and security teams should prioritize patching this vulnerability. The C [truncated]
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6. This vulnerability allows authenticated attackers with administrator-level access to append additional SQL queries into existing queries, potentially leading to the extraction of sensitive information from the database. Administrators and [truncated]
CVE-2026-39451 is a MEDIUM severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WP Google Review Slider plugin versions <= 18.0. The vulnerability has a CVSS score of 6.3 and was published on {cvePublishedAt}.
CVE-2019-25745 is a time-based blind SQL injection vulnerability in WordPress Plugin Google Review Slider 6.1. The vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques.