WPHizmet

Eklenti güvenlik geçmişi

wp-review-slider-pro güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) wp-review-slider-pro eklentisi için 3 açık kaydı bulunuyor; en yenisi 26 Eylül 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 0 tanesi oturum açmadan istismar edilebiliyor.

Toplam kayıt
3
Kritik veya yüksek
2
Oturumsuz istismar
0
Son kayıt
26 Eylül 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-84097Orta · 6,526 Eylül 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 12.7.12 öncesi

    The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to unauthenticated visitors.

  • CVE-2026-84096Yüksek · 8,026 Eylül 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 12.7.12 öncesi

    The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-84095Yüksek · 8,026 Eylül 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 12.7.12 öncesi

    The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.

    Türkçe kayıt ve ne yapmalı

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.