Impact
The WP TripAdvisor Review Slider plugin for WordPress contains a generic SQL injection flaw in the 'filtersource' parameter in all releases up to 14.6. Insufficient escaping and the absence of prepared statements allow an attacker with administrator-level authentication to inject arbitrary SQL, which can then be used to retrieve sensitive database information. This weakness is classified as CWE-89.
Affected Systems
All installations of the jgwhite33 WP TripAdvisor Review Slider plugin on WordPress sites that use version 14.6 or earlier are affected. The vulnerability does not depend on specific WordPress core versions or additional plugins.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium severity, while the EPSS score of less than 1% shows a low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an authenticated attacker who has gained administrator or higher privileges on the WordPress site; such a user can craft requests that include malicious payloads in the 'filtersource' parameter, leading to data exfiltration.
OpenCVE Enrichment