CVE-2025-26946
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-26946 is a critical SQL Injection vulnerability affecting WP Yelp Review Slider from version n/a through 8.1. An attacker can exploit this issue by injecting malicious SQL commands into the plugin, bypassing input validation. The vulnerability allows blind SQL injection, enabling an attacker to extract sensitive information, modify data, or even execute arbitrary code. This puts websites using the WP Yelp Review Slider plugin at risk of data breaches and unauthorized access. It is recommended to apply the latest patch or upgrade to a secure version of the plugin as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.