cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-google-places-review-slider wp-google-places-review-slider

Direction: ascending
Jun 06, 2024

WP Google Review Slider # CVE-2023-0259

CVE, Research URL

CVE-2023-0259

Date
Feb 13, 2023
Research Description
The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
Affected versions
max 11.8.
Status
vulnerable

WP Google Review Slider # e42cedcff159170074fe08dcc12e3cd44aae4dcf

Date
Nov 01, 2019
Research Description
WP Google Review Slider [wp-google-places-review-slider] < 6.2 WordPress WP Google Review Slider <= 6.1 - Authenticated SQL Injection (SQLi) vulnerability Authenticated SQL Injection (SQLi) vulnerability found by Princy Edward in WordPress WP Google Review Slider (versions <= 6.1).
Affected versions
max 6.2.
Status
vulnerable

WP Google Review Slider # CVE-2022-4242

CVE, Research URL

CVE-2022-4242

Date
Dec 26, 2022
Research Description
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 11.6.
Status
vulnerable

WP Google Review Slider # CVE-2024-2310

CVE, Research URL

CVE-2024-2310

Date
Apr 26, 2024
Research Description
The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 13.6.
Status
vulnerable
Jul 24, 2024

WP Google Review Slider # PSC-2024-64514

PSC, Research URL

PSC-2024-64514

Date
Aug 05, 2025
Research Description
WP Google Review Slider is an essential tool for WordPress site owners looking to display their Google reviews quickly and effectively. With this plugin, you can effortlessly showcase your hard-earned 5-star reviews in a stylish slider or responsive grid. This not only boosts customer confidence but also enhances social proof, ultimately driving more sales.
Affected versions
Min 18.4, max 18.4.
Status
SAFE & CERTIFIED
Mar 28, 2025

WP Google Review Slider # CVE-2025-30783

CVE, Research URL

CVE-2025-30783

Date
Mar 27, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows SQL Injection.This issue affects WP Google Review Slider: from n/a through <= 16.0.
Affected versions
max 16.1.
Status
vulnerable
May 17, 2025

WP Google Review Slider # CVE-2024-11109

CVE, Research URL

CVE-2024-11109

Date
May 16, 2025
Research Description
The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 15.6.
Status
vulnerable
Dec 10, 2025

WP Google Review Slider # CVE-2025-66063

CVE, Research URL

CVE-2025-66063

Date
Nov 21, 2025
Research Description
Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.
Affected versions
max 17.6.
Status
vulnerable
Jun 06, 2026

WP Google Review Slider # CVE-2019-25745

CVE, Research URL

CVE-2019-25745

Date
Jun 04, 2026
Research Description
WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques.
Affected versions
max 6.1.
Status
vulnerable
Jun 10, 2026

WP Google Review Slider # CVE-2026-39451

CVE, Research URL

CVE-2026-39451

Date
Jun 16, 2026
Research Description
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
Affected versions
max 17.9.
Status
vulnerable
Jun 13, 2026

WP Google Review Slider # CVE-2023-33999

CVE, Research URL

CVE-2023-33999

Date
Jun 11, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
Affected versions
max 12.6.
Status
vulnerable
Jun 16, 2026

WP Google Review Slider # a12fe67d-2359-43a4-991c-cbe11bada7d8

Date
-
Research Description
WP Google Review Slider [wp-google-places-review-slider] < 6.2 WP Google Review Slider &lt;= 6.1 - Authenticated SQL Injection tid parameter vulnerable to SQLi. Note (WPScanTeam): v6.1 has been pathed directly in the tags (https://plugins.trac.wordpress.org/browser/wp-google-places-review-slider/tags/6.1/admin/partials/templates_posts.php#L58). However the the issue can be verified with v6.0)
Affected versions
max 6.2.
Status
vulnerable
Jul 02, 2026

WP Google Review Slider # CVE-2026-13015

CVE, Research URL

CVE-2026-13015

Date
Jul 01, 2026
Research Description
The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Affected versions
max 18.2.
Status
vulnerable