Impact
The vulnerability is a time-based blind SQL injection that allows unauthenticated attackers to inject malicious SQL code through the 'tid' parameter of the Google Review Slider plugin. By sending crafted GET requests to the admin interface, attackers can cause the database to execute arbitrary SQL, which can be used to extract sensitive data. The flaw results in disclosure of confidential information and is identified by CWE-89.
Affected Systems
The issue affects the WordPress plugin Google Review Slider version 6.1, published by jgwhite33. Impacted systems are WordPress installations that have this plugin deployed and have the admin interface exposed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The exploit is likely to be performed via HTTP GET requests to the unprotected admin area, and it does not require authentication. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and lack of authentication requirement still pose a serious risk of data theft.
OpenCVE Enrichment