plugin

Wp Google Places Review Slider Vulnerabilities

21 known security issues reported for the Wp Google Places Review Slider WordPress plugin. Most recent disclosed Jul 27, 2026.

3 high 9 medium

Running Wp Google Places Review Slider on your site? Check whether your installed version is affected.

Scan your site free

Google Review Slider <= 18.4 - Authenticated (Administrator+) SQL Injection

medium

The Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 18.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level acces...

CVSS:
4.9
Affected:
up to 18.4
Fixed in:
18.5
Disclosed:
Jul 27, 2026

CVE-2026-66427 on NVD →

Google Review Slider <= 18.4 - Cross-Site Request Forgery

medium

The Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 18.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they c...

CVSS:
4.3
Affected:
up to 18.4
Fixed in:
18.5
Disclosed:
Jul 27, 2026

CVE-2026-66428 on NVD →

WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter

medium

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decode...

CVSS:
6.1
Affected:
up to 18.1
Fixed in:
18.2
Disclosed:
Jun 30, 2026

CVE-2026-13015 on NVD →

WP Google Review Slider <= 6.1 - Unauthenticated SQL Injection

high

The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu...

CVSS:
7.5
Affected:
up to 6.1
Fix:
No patched version reported
Disclosed:
Jun 4, 2026

CVE-2019-25745 on NVD →

WP Google Review Slider <= 18.0 - Unauthenticated Stored Cross-Site Scripting

high

The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 18.0
Fixed in:
18.1
Disclosed:
Jun 1, 2026

CVE-2026-39451 on NVD →

WP Google Review Slider [wp-google-places-review-slider] <= 17.4

unknown

[en] Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.

Affected:
up to 17.4
Fixed in:
17.4
Disclosed:
Nov 21, 2025

CVE-2025-66063 on NVD →

Google Review Slider <= 17.4 - Missing Authorization

medium

The WP Google Review Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 17.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 17.4
Fixed in:
17.6
Disclosed:
Nov 14, 2025

CVE-2025-66063 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 15.6

unknown

[en] The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 15.6
Fixed in:
15.6
Disclosed:
May 15, 2025

CVE-2024-11109 on NVD →

WP Google Review Slider <= 16.0 - Cross-Site Request Forgery to SQL Injection

medium

The WP Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 16.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject SQL queries via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 16.0
Fixed in:
16.1
Disclosed:
Mar 27, 2025

CVE-2025-30783 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 16.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider allows SQL Injection. This issue affects WP Google Review Slider: from n/a through 16.0.

Affected:
up to 16.1
Fixed in:
16.1
Disclosed:
Mar 27, 2025

CVE-2025-30783 on NVD →

WP Google Review Slider <= 15.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...

CVSS:
4.4
Affected:
up to 15.5
Fixed in:
15.6
Disclosed:
Mar 3, 2025

CVE-2024-11109 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 13.6

unknown

[en] The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 13.6
Fixed in:
13.6
Disclosed:
Apr 26, 2024

CVE-2024-2310 on NVD →

WP Google Review Slider <= 13.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...

CVSS:
4.4
Affected:
up to 13.5
Fixed in:
13.6
Disclosed:
Apr 5, 2024

CVE-2024-2310 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
11.2 – 12.5
Fixed in:
12.6
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 11.8

unknown

[en] The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

Affected:
up to 11.8
Fixed in:
11.8
Disclosed:
Feb 13, 2023

CVE-2023-0259 on NVD →

WP Google Review Slider <= 11.7 - Authenticated (Subscriber+) SQL Injection

high

The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid parameter in versions up to, and including, 11.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...

CVSS:
8.8
Affected:
up to 11.7
Fixed in:
11.8
Disclosed:
Jan 23, 2023

CVE-2023-0259 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 11.6

unknown

[en] The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 11.6
Fixed in:
11.6
Disclosed:
Dec 26, 2022

CVE-2022-4242 on NVD →

WP Google Review Slider <= 11.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scr...

CVSS:
5.5
Affected:
up to 11.5
Fixed in:
11.6
Disclosed:
Dec 2, 2022

CVE-2022-4242 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 6.2

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Princy Edward in WordPress WP Google Review Slider (versions <= 6.1).

Affected:
up to 6.2
Fixed in:
6.2
Disclosed:
Nov 1, 2019

WP Google Review Slider [wp-google-places-review-slider] < 12.6

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 12.6
Fixed in:
12.6

CVE-2023-33999 on NVD →

WP Google Review Slider [wp-google-places-review-slider] < 6.2

unknown

tid parameter vulnerable to SQLi. Note (WPScanTeam): v6.1 has been pathed directly in the tags (https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/tags/6.1/admin/partials/templates_posts.php#L58). However the the issue can be verified with v6.0)

Affected:
up to 6.2
Fixed in:
6.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database