jgwhite33 Vulnerabilities and Affected Products
Vulnerabilities associated with WP Google Review Slider.
Products
Clear product- WP Google Review Slider6 vulnerabilities
- WP TripAdvisor Review Slider3 vulnerabilities
- WP Airbnb Review Slider2 vulnerabilities
- Google Review Slider1 vulnerability
- WP Review Slider1 vulnerability
- WP Thumbtack Review Slider1 vulnerability
- WP Yelp Review Slider1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66428MEDIUM | WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery (CSRF) vulnerabilityUnauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. CWE-352Jul 27, 2026 | CVSS4.3v3.1 | EPSS0.098% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66427HIGH | WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerabilityAdministrator SQL Injection in WP Google Review Slider <= 18.4 versions. CWE-89Jul 27, 2026 | CVSS7.6v3.1 | EPSS0.226% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13015MEDIUM | WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' ParameterThe Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option.… CWE-79Jul 1, 2026 | CVSS6.1v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39451MEDIUM | WordPress WP Google Review Slider plugin <= 18.0 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. CWE-79Jun 15, 2026 | CVSS6.3v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66063MEDIUM | WordPress WP Google Review Slider plugin <= 17.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4. CWE-862Nov 21, 2025 | CVSS5.4v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30783HIGH | WordPress WP Google Review Slider plugin <= 16.0 - CSRF to SQL Injection vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows SQL Injection.This issue affects WP Google Review Slider: from n/a through <= 16.0. CWE-352Mar 27, 2025 | CVSS8.2v3.1 | EPSS0.212% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |