Impact
An unauthenticated Cross Site Request Forgery flaw exists in the WP Google Review Slider plugin versions 18.4 and older. The vulnerability allows an attacker to craft and send forged HTTP requests through a victim’s browser. If a user is logged into the WordPress site, the attacker can trigger privileged actions via the plugin—such as modifying slider settings or adding reviews—without the user’s consent, potentially compromising content integrity. Based on the description, it is inferred that the plugin enables these specific actions, but the exact impact is not explicitly stated in the CVE.
Affected Systems
All installations of the WordPress plugin WP Google Review Slider by jgwhite33 that use version 18.4 or earlier are affected. The plugin must be updated to version 18.5 or newer to eliminate the CSRF flaw.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed large‑scale exploitation yet. Administrators should treat it as a medium‑risk exposure until a vendor patch is applied.
OpenCVE Enrichment