SQL Injection Vulnerability in WP Yelp Review Slider from jgwhite33
CVE-2025-26946
7.6HIGH
Key Information:
- Vendor
- Jgwhite33
- Status
- WP Yelp Review Slider
- Vendor
- CVE Published:
- 25 February 2025
Summary
An SQL Injection vulnerability exists in the WP Yelp Review Slider plugin developed by jgwhite33. This vulnerability arises from improper sanitization of special elements used in SQL commands, leading to the potential for Blind SQL Injection attacks. It affects versions of the plugin from an unspecified release up to and including version 8.1. Attackers could exploit this flaw to manipulate database queries, potentially gaining unauthorized access to sensitive information stored in the database. Users are urged to evaluate their installations and apply necessary security updates to mitigate this risk.
Affected Version(s)
WP Yelp Review Slider <= 8.1
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock (Patchstack Alliance)