WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jgwhite33
Jgwhite33 wp Google Review Slider Wordpress Wordpress wordpress |
|
| Vendors & Products |
Jgwhite33
Jgwhite33 wp Google Review Slider Wordpress Wordpress wordpress |
Thu, 04 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract sensitive database information using time-based blind SQL injection techniques. | |
| Title | WordPress Plugin Google Review Slider 6.1 SQL Injection via tid | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-04T13:22:48.282Z
Updated: 2026-06-04T14:33:25.582Z
Reserved: 2026-06-04T11:24:45.478Z
Link: CVE-2019-25745
Updated: 2026-06-04T14:33:22.171Z
Status : Deferred
Published: 2026-06-04T14:16:33.883
Modified: 2026-06-04T15:00:40.757
Link: CVE-2019-25745
No data.