Executive brief
WP Google Review Slider, a WordPress plugin used to display Google business reviews on websites, contains a security flaw that could allow an administrative user to execute unauthorized database commands. If exploited, an attacker with high-level access could potentially steal sensitive information from the site's database or cause service disruptions. While the risk is mitigated by the requirement for administrator privileges, organizations should update the plugin to prevent potential internal abuse or escalation from compromised accounts.
Technical details
A SQL injection vulnerability exists in the WP Google Review Slider plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 18.4. An attacker with Administrator-level privileges can exploit this vulnerability via network requests to interact directly with the underlying database. Successful exploitation could lead to unauthorized data exfiltration or limited impact on database availability. The issue has been addressed in version 18.5.
Affected products
- jgwhite33 WP Google Review Slider <= 18.4
Timeline
- 2026-07-06: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-27: advisory: NVD and Patchstack published advisory details
- 2026-07-27: patched: Version 18.5 released to address the vulnerability