SQL Injection Vulnerability in WP Yelp Review Slider from jgwhite33
CVE-2025-26946
What is CVE-2025-26946?
An SQL Injection vulnerability exists in the WP Yelp Review Slider plugin developed by jgwhite33. This vulnerability arises from improper sanitization of special elements used in SQL commands, leading to the potential for Blind SQL Injection attacks. It affects versions of the plugin from an unspecified release up to and including version 8.1. Attackers could exploit this flaw to manipulate database queries, potentially gaining unauthorized access to sensitive information stored in the database. Users are urged to evaluate their installations and apply necessary security updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Yelp Review Slider <= 8.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved