VYPR

Wp Yelp Review Slider

by WordPress

Source repositories

CVEs (5)

  • CVE-2023-0263HigFeb 13, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

  • CVE-2023-0260HigFeb 13, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

  • CVE-2025-26946HigFeb 25, 2025
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider wp-yelp-review-slider allows Blind SQL Injection.This issue affects WP Yelp Review Slider: from n/a through <= 8.1.

  • CVE-2026-93778HigSep 22, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2022-0383HigFeb 28, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks