SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66428

MEDIUM · CVSS 4.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The WP Google Review Slider plugin versions up to 18.4 are vulnerable to an unauthenticated Cross-Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of users without their consent. This vulnerability poses a medium risk, particularly for websites that utilize this plugin, as it could lead to unauthorized changes or data manipulation. Website administrators using this plugin should prioritize updating to a patched version to mitigate potential exploitation risks.

CVE
CVE-2026-66428
Severity
MEDIUM
CVSS
4.3
EPSS
0.10%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.