Description
Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.
Published: 2025-11-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes a missing authorization flaw in WP Google Review Slider. The flaw permits an attacker to perform actions that should be restricted, such as viewing, editing, or deleting review data, by exploiting incorrectly configured access control levels. This can lead to unauthorized modification of content or disabling of the review feature, compromising the integrity of the site’s review system.

Affected Systems

The vulnerability affects the WordPress plugin WP Google Review Slider (author jgwhite33). All releases from the earliest available version up to and including 17.4 are susceptible. Site administrators who have not upgraded the plugin since before 17.5 are at risk.

Risk and Exploitability

The CVSS base score is 5.4, placing the issue in the moderate severity range. The EPSS score indicates that the likelihood of public exploitation is less than 1 %, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s exposed administration interface or REST endpoints, where an authenticated user or an attacker with access to the admin area can trigger the unauthorized actions described. While exploitation does not appear to require additional system privileges, it relies on the plugin’s default configuration being overly permissive.

Generated by OpenCVE AI on April 29, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Google Review Slider to the latest version (17.5 or newer) to apply the vendor‑supplied fix.
  • Restrict user roles that have permission to manage the review slider or disable the plugin’s REST API endpoints if unused.
  • Review and tighten the WordPress permission hierarchy to ensure that only trusted administrators can access the review slider settings.

Generated by OpenCVE AI on April 29, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Jgwhite33
Jgwhite33 wp Google Review Slider
Wordpress
Wordpress wordpress
Vendors & Products Jgwhite33
Jgwhite33 wp Google Review Slider
Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.
Title WordPress WP Google Review Slider plugin <= 17.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Jgwhite33 Wp Google Review Slider
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:15.490Z

Reserved: 2025-11-21T11:20:46.955Z

Link: CVE-2025-66063

cve-icon Vulnrichment

Updated: 2025-11-21T16:23:59.230Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:47.197

Modified: 2026-04-27T18:16:32.290

Link: CVE-2025-66063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:15:19Z

Weaknesses