Junglewise Threat Intelligence

CVE-2026-8443: WP Review Slider Pro SQL injection in wppro_get_overall_chart_data

CVE-2026-8443 · Severity: high · CVSS 8.8 · Published 2026-06-16

Technologies: WP Review Slider Review Slider, WP Review Slider Pro. Vendors: WP Review Slider.

Executive brief

The WP Review Slider Pro plugin for WordPress, which is used to display customer reviews from various social platforms, contains a security vulnerability that allows logged-in users to interfere with the site's database. By sending specially crafted requests, an attacker with even low-level 'Subscriber' permissions can view sensitive information that they are not authorized to see. This could lead to the exposure of private customer data or site configuration details, potentially compromising the entire website.

Technical details

A SQL injection vulnerability exists in the WP Review Slider Pro plugin due to improper handling of user-supplied JSON strings in the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action. The plugin uses stripslashes() on these strings before calling json_decode(), which bypasses WordPress's built-in magic quotes protection. The resulting array values are then concatenated directly into SQL WHERE clauses without parameterization or use of $wpdb->prepare(). Authenticated attackers with Subscriber-level access or higher can exploit this to execute arbitrary SQL queries and extract sensitive data. The vulnerability is further simplified for attackers because the AJAX handler returns the executed SQL string in its JSON response, facilitating the construction of exploitation oracles.

Affected products

  • WP Review Slider WP Review Slider Pro up to, and including, 12.6.8

Timeline

  • 2026-06-16: disclosed: CVE published to NVD dataset
  • 2026-06-16: advisory: Wordfence advisory published

References