WP Google Review Slider Cross-Site Request Forgery Vulnerability Allowing SQL Injection
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Google Review Slider plugin for WordPress, affecting versions through 16.0. This vulnerability allows for SQL Injection, as it enables attackers to trick users with higher privileges into performing actions that could manipulate the database.
Impact
Exploitation of this vulnerability could lead to SQL Injection, allowing attackers to interfere with the database queries of the application. This could result in unauthorized data access, data manipulation, or in some cases, executing administrative operations.
Remediation
Users of the WP Google Review Slider plugin should update to version 16.1 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
