Junglewise Threat Intelligence

CVE-2026-66428: jgwhite33 WP Google Review Slider CSRF

CVE-2026-66428 · Severity: medium · CVSS 4.3 · Published 2026-07-27

Vendors: Jgwhite33.

Executive brief

WP Google Review Slider is a WordPress plugin used to display Google business reviews on websites. A security flaw allows an attacker to trick a site administrator into performing unintended actions, such as changing plugin settings or deleting data, by clicking a malicious link. This could lead to unauthorized configuration changes that impact how reviews are displayed to customers.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Google Review Slider plugin for WordPress (versions 18.4 and below) due to missing or insufficient nonce validation. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it (e.g., via a phishing link). Successful exploitation allows the attacker to perform administrative actions within the plugin's context, such as modifying settings, without the user's intent. The issue is resolved in version 18.5.

Affected products

  • jgwhite33 WP Google Review Slider <= 18.4

Timeline

  • 2026-07-06: other: Reported by researcher
  • 2026-07-27: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD

References

Related threats