SQL Injection Vulnerability in WP Yelp Review Slider from jgwhite33
CVE-2025-26946

7.6HIGH

Key Information:

Vendor
Jgwhite33
Status
WP Yelp Review Slider
Vendor
CVE Published:
25 February 2025

Summary

An SQL Injection vulnerability exists in the WP Yelp Review Slider plugin developed by jgwhite33. This vulnerability arises from improper sanitization of special elements used in SQL commands, leading to the potential for Blind SQL Injection attacks. It affects versions of the plugin from an unspecified release up to and including version 8.1. Attackers could exploit this flaw to manipulate database queries, potentially gaining unauthorized access to sensitive information stored in the database. Users are urged to evaluate their installations and apply necessary security updates to mitigate this risk.

Affected Version(s)

WP Yelp Review Slider <= 8.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.