CVE-2026-8441
https://wpreviewslider.com/ WP Review Slider Pro
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but does not provide SQL safety. The value is then concatenated directly into a numeric/unquoted `AND id NOT IN (...)` clause and executed via $wpdb->get_results() without $wpdb->prepare() or intval() casting. Because the value sits in an unquoted numeric context, WordPress's wp_mag...
- CVSS
- 7.5
- EPSS
- 0.37% 29.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.02