CVE-2026-8444: Https://wpreviewslider.com/ Wp Review Slider Pro
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected products
- Https://wpreviewslider.com/ Wp Review Slider Pro: up to and including 12.6.8
Published 2026-06-16. Last modified 2026-06-17.