CVE-2026-8443
https://wpreviewslider.com/ WP Review Slider Pro
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which removes the escaping applied by WordPress's wp_magic_quotes; the resulting decoded array values are then concatenated directly into SQL WHERE clauses without parameterization, and the constructed query is executed via $wpdb->get_results() without $wpdb->prepare(). This makes it possi...
- CVSS
- 8.8
- EPSS
- 0.34% 25.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.16