Description
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
Published: 2026-07-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Request Forgery flaw exists in the WP Google Review Slider plugin versions 18.4 and older. The vulnerability allows an attacker to craft and send forged HTTP requests through a victim’s browser. If a user is logged into the WordPress site, the attacker can trigger privileged actions via the plugin—such as modifying slider settings or adding reviews—without the user’s consent, potentially compromising content integrity. Based on the description, it is inferred that the plugin enables these specific actions, but the exact impact is not explicitly stated in the CVE.

Affected Systems

All installations of the WordPress plugin WP Google Review Slider by jgwhite33 that use version 18.4 or earlier are affected. The plugin must be updated to version 18.5 or newer to eliminate the CSRF flaw.

Risk and Exploitability

The CVSS score of 4.3 classifies the vulnerability as medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed large‑scale exploitation yet. Administrators should treat it as a medium‑risk exposure until a vendor patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 17:26 UTC.

Remediation

Vendor Solution

Update the WordPress WP Google Review Slider Plugin to the latest available version (at least 18.5).


OpenCVE Recommended Actions

  • Update the WP Google Review Slider plugin to version 18.5 or later.
  • If the plugin is not required, uninstall it to eliminate the attack surface.
  • Enable two‑factor authentication for WordPress administrator accounts to reduce the impact of potential CSRF attempts.

Generated by OpenCVE AI on August 3, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Jgwhite33
Jgwhite33 wp Google Review Slider
Wordpress
Wordpress wordpress
Vendors & Products Jgwhite33
Jgwhite33 wp Google Review Slider
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
Title WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Jgwhite33 Wp Google Review Slider
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:59:35.991Z

Reserved: 2026-07-27T09:00:08.213Z

Link: CVE-2026-66428

cve-icon Vulnrichment

Updated: 2026-07-27T14:59:32.355Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:10.780

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-66428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)