Executive brief
The WP TripAdvisor Review Slider plugin for WordPress, which displays TripAdvisor reviews on websites, contains a security flaw that could allow an administrator to access sensitive information from the site's database. By exploiting this vulnerability, a high-level user could run unauthorized database commands to extract data they are not supposed to see. While this requires administrative access, it poses a risk to data confidentiality and overall site integrity.
Technical details
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to SQL Injection via the 'filtersource' parameter in versions up to and including 14.6. The root cause is insufficient escaping of user-supplied input and a lack of proper SQL query preparation using WordPress's $wpdb->prepare() or similar mechanisms. An authenticated attacker with administrator-level privileges can exploit this by appending malicious SQL queries to existing ones. This enables the extraction of sensitive data from the WordPress database. A patch appears to be available in the latest changeset (3607754).
Affected products
- jgwhite33 WP TripAdvisor Review Slider up to, and including, 14.6
Timeline
- 2026-07-16: disclosed: Vulnerability published to the CVE list
- 2026-07-16: advisory: Wordfence and NVD published details
References
- https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/admin/class-wp-tripadvisor-review-slider-admin.php
- https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display-widget.php
- https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display.php
- https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.6/public/partials/wp-tripadvisor-review-slider-public-display.php
- https://plugins.trac.wordpress.org/changeset/3607754/wp-tripadvisor-review-slider
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a0d38788-5f90-4ab1-8df1-1c67c1052e6d?source=cve