Ljapps
Ljapps WP Google Review Slider: vulnerabilidades y CVE
Ljapps WP Google Review Slider tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66428 | Media (4.3) | 0.14% | — | 27 jul 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. |
| CVE-2026-66427 | Alta (7.6) | 0.38% | — | 27 jul 2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. |
| CVE-2026-39451 | Media (6.3) | 0.25% | — | 15 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. |
| CVE-2024-11109 | Media (4.8) | 0.31% | — | 15 may 2025 | The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when… |
| CVE-2024-2310 | Media (5.9) | 0.31% | — | 26 abr 2024 | The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when… |
| CVE-2023-0259 | Alta (8.8) | 0.92% | — | 13 feb 2023 | The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as… |
| CVE-2022-4242 | Media (4.8) | 0.53% | — | 26 dic 2022 | The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.