Impact
The vulnerability allows authenticated attackers with administrator-level access to inject arbitrary SQL through the curselrevs[] parameter due to lack of escaping. This can lead to extraction of sensitive database content, compromising the confidentiality of WordPress site data.
Affected Systems
Affected assets are the WP TripAdvisor Review Slider plugin for WordPress from vendor jgwhite33. All releases up to and including version 14.3 contain the flaw; later releases (14.4 and beyond) are presumed fixed. WordPress installations running any of these versions are potentially exploitable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and EPSS is not available, suggesting no known high exploitation probability. Because the issue requires authenticated administrator credentials, the risk is confined to sites with privileged user accounts. The vulnerability is not listed in CISA KEV, but superusers or shared administrative accounts increase exposure.
OpenCVE Enrichment