Eklenti güvenlik geçmişi
wp-review-slider-pro güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) wp-review-slider-pro eklentisi için 3 açık kaydı bulunuyor; en yenisi 26 Eylül 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 0 tanesi oturum açmadan istismar edilebiliyor.
- Toplam kayıt
- 3
- Kritik veya yüksek
- 2
- Oturumsuz istismar
- 0
- Son kayıt
- 26 Eylül 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
SQL enjeksiyonu
Etkilenen sürümler: 12.7.12 öncesi
The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to unauthenticated visitors.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 12.7.12 öncesi
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.
Türkçe kayıt ve ne yapmalıdepolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 12.7.12 öncesi
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.
Türkçe kayıt ve ne yapmalı
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.