Impact
The vulnerability is a classic SQL injection flaw that affects WordPress sites running the WP Google Review Slider plugin version 18.4 or earlier. An authenticated site administrator can supply crafted input that bypasses the plugin’s input validation, which is a CWE‑89 weakness, and inject arbitrary SQL statements. The result of a successful attack is unauthorized reading of database contents, which can expose sensitive site data, or modification of data that could alter website content or user information.
Affected Systems
The impacted product is the WP Google Review Slider plugin by jgwhite33, widely used on WordPress installations. Any deployment of the plugin at version 18.4 or earlier is vulnerable. The vulnerability is specific to those older releases; newer releases, starting with 18.5, have been patched.
Risk and Exploitability
The CVSS v3 score of 7.6 signals a high risk rating, and the attack requires authentication as a WordPress administrator, indicating that the attacker must first compromise or have access to an administrative account. The EPSS score of 0.00226 (<1%) indicates a very low probability of exploitation, and the lack of KEV listing suggests no widespread zero‑day exploitation has been reported yet. Nonetheless, the flaw exposes confidential data and could lead to further attacks if the database is compromised.
OpenCVE Enrichment