PT-2023-16121 · WordPress · Wp Tripadvisor Review Slider

Lana Codes

·

Published

2023-02-13

·

Updated

2023-02-15

·

CVE-2023-0261

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP TripAdvisor Review Slider WordPress plugin versions prior to 10.8
Description The issue arises from improper sanitization and escaping of a parameter before its use in a SQL statement, resulting in a SQL injection that can be exploited by users with a role as low as subscriber.
Recommendations For versions prior to 10.8, update to version 10.8 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2023-0261

Affected Products

Wp Tripadvisor Review Slider