860
VMScore

CVE-2025-26946

CVSSv4: NA | CVSSv3: 7.6 | CVSSv2: NA | VMScore: 860 | EPSS: 0.00045 | KEV: Not Included
Published: 25/02/2025 Updated: 25/02/2025

Vulnerability Summary

SQL Injection in WP Yelp Review Slider Enabling Blind Database Manipulation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a up to and including 8.1.

Solution

Update the WordPress WP Yelp Review Slider wordpress plugin to the latest available version (at least 8.2).
Vulnerable Product Search on Vulmon Subscribe to Product

jgwhite33 wp yelp review slider