Executive brief
Verified Reviews (Avis Vérifiés) is a WordPress plugin that manages customer reviews. An unauthenticated SQL injection vulnerability in versions 2.4.6 and earlier allows attackers to read, modify, or delete the entire WordPress database without logging in, exposing user accounts, passwords, and sensitive business data.
Technical details
The vulnerability is an unauthenticated SQL injection (CWE-89) in the Verified Reviews WordPress plugin affecting versions up to 2.4.6. The plugin fails to properly sanitize user input before using it in database queries, allowing attackers to inject arbitrary SQL commands. No authentication is required to exploit this vulnerability; an attacker can craft a malicious request over the network to execute SQL commands directly. This enables full database compromise including reading, modifying, or deleting all data. No official patch is currently available; mitigation via web application firewall rules is recommended as a temporary measure.
Affected products
- WordPress Verified Reviews (Avis Vérifiés) <=2.4.6
Timeline
- 2026-09-10: disclosed: Published on NVD
- 2026-09-09: advisory: Reported to Patchstack