Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ljapps Subscribe
Filtered by product Wp Review Slider
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0260 1 Ljapps 1 Wp Review Slider 2023-02-15 N/A 8.8 HIGH
The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
CVE-2022-0383 1 Ljapps 1 Wp Review Slider 2022-03-08 6.5 MEDIUM 7.2 HIGH
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks