VYPR
Medium severity5.4NVD Advisory· Published Nov 21, 2025· Updated Apr 27, 2026

CVE-2025-66063

CVE-2025-66063

Description

Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WP Google Review Slider plugin <=17.4 allows attackers to exploit incorrectly configured access controls, potentially leading to unauthorized actions.

Vulnerability

Overview The WP Google Review Slider plugin for WordPress (versions up to and including 17.4) suffers from a missing authorization vulnerability. This flaw stems from improperly configured access control security levels, allowing an attacker to bypass intended restrictions and perform actions that should require higher privileges. [1]

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending crafted requests to the vulnerable plugin's functions that lack proper authorization checks. No special network position is required; the attack can be carried out remotely over the web. The vulnerability is categorized as a broken access control issue, common in mass-exploit campaigns targeting multiple WordPress sites. [1]

Impact

Successful exploitation could enable an attacker to perform unauthorized operations, such as modifying or deleting data, depending on the specific missing restrictions. While the CVSS score is 5.4 (medium), the actual impact may vary based on the privileges that can be gained. [1]

Mitigation

The vendor has released version 17.6 to address the vulnerability. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins. As a temporary workaround, if immediate update is not possible, contacting a hosting provider or web developer for assistance is recommended. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.