Google Review Slider <= 18.4 - Authenticated (Administrator+) SQL Injection
medium
The Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 18.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level acces...
- CVSS:
- 4.9
- Affected:
- up to 18.4
- Fixed in:
- 18.5
- Disclosed:
- Jul 27, 2026
CVE-2026-66427 on NVD →
Google Review Slider <= 18.4 - Cross-Site Request Forgery
medium
The Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 18.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they c...
- CVSS:
- 4.3
- Affected:
- up to 18.4
- Fixed in:
- 18.5
- Disclosed:
- Jul 27, 2026
CVE-2026-66428 on NVD →
WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter
medium
The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decode...
- CVSS:
- 6.1
- Affected:
- up to 18.1
- Fixed in:
- 18.2
- Disclosed:
- Jun 30, 2026
CVE-2026-13015 on NVD →
WP Google Review Slider <= 6.1 - Unauthenticated SQL Injection
high
The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu...
- CVSS:
- 7.5
- Affected:
- up to 6.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2026
CVE-2019-25745 on NVD →
WP Google Review Slider <= 18.0 - Unauthenticated Stored Cross-Site Scripting
high
The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 7.2
- Affected:
- up to 18.0
- Fixed in:
- 18.1
- Disclosed:
- Jun 1, 2026
CVE-2026-39451 on NVD →
WP Google Review Slider [wp-google-places-review-slider] <= 17.4
unknown
[en] Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.
- Affected:
- up to 17.4
- Fixed in:
- 17.4
- Disclosed:
- Nov 21, 2025
CVE-2025-66063 on NVD →
Google Review Slider <= 17.4 - Missing Authorization
medium
The WP Google Review Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 17.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 17.4
- Fixed in:
- 17.6
- Disclosed:
- Nov 14, 2025
CVE-2025-66063 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 15.6
unknown
[en] The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 15.6
- Fixed in:
- 15.6
- Disclosed:
- May 15, 2025
CVE-2024-11109 on NVD →
WP Google Review Slider <= 16.0 - Cross-Site Request Forgery to SQL Injection
medium
The WP Google Review Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 16.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject SQL queries via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 16.0
- Fixed in:
- 16.1
- Disclosed:
- Mar 27, 2025
CVE-2025-30783 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 16.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider allows SQL Injection. This issue affects WP Google Review Slider: from n/a through 16.0.
- Affected:
- up to 16.1
- Fixed in:
- 16.1
- Disclosed:
- Mar 27, 2025
CVE-2025-30783 on NVD →
WP Google Review Slider <= 15.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 4.4
- Affected:
- up to 15.5
- Fixed in:
- 15.6
- Disclosed:
- Mar 3, 2025
CVE-2024-11109 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 13.6
unknown
[en] The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 13.6
- Fixed in:
- 13.6
- Disclosed:
- Apr 26, 2024
CVE-2024-2310 on NVD →
WP Google Review Slider <= 13.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to i...
- CVSS:
- 4.4
- Affected:
- up to 13.5
- Fixed in:
- 13.6
- Disclosed:
- Apr 5, 2024
CVE-2024-2310 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 11.2 – 12.5
- Fixed in:
- 12.6
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 11.8
unknown
[en] The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
- Affected:
- up to 11.8
- Fixed in:
- 11.8
- Disclosed:
- Feb 13, 2023
CVE-2023-0259 on NVD →
WP Google Review Slider <= 11.7 - Authenticated (Subscriber+) SQL Injection
high
The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid parameter in versions up to, and including, 11.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...
- CVSS:
- 8.8
- Affected:
- up to 11.7
- Fixed in:
- 11.8
- Disclosed:
- Jan 23, 2023
CVE-2023-0259 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 11.6
unknown
[en] The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 11.6
- Fixed in:
- 11.6
- Disclosed:
- Dec 26, 2022
CVE-2022-4242 on NVD →
WP Google Review Slider <= 11.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scr...
- CVSS:
- 5.5
- Affected:
- up to 11.5
- Fixed in:
- 11.6
- Disclosed:
- Dec 2, 2022
CVE-2022-4242 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 6.2
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Princy Edward in WordPress WP Google Review Slider (versions <= 6.1).
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Nov 1, 2019
WP Google Review Slider [wp-google-places-review-slider] < 12.6
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 12.6
- Fixed in:
- 12.6
CVE-2023-33999 on NVD →
WP Google Review Slider [wp-google-places-review-slider] < 6.2
unknown
tid parameter vulnerable to SQLi.
Note (WPScanTeam): v6.1 has been pathed directly in the tags (https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/tags/6.1/admin/partials/templates_posts.php#L58). However the the issue can be verified with v6.0)
- Affected:
- up to 6.2
- Fixed in:
- 6.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database