CVE-2026-81800
moderateUnauthenticated SQL Injection in WordPress Verified Reviews (Avis Vérifiés) Plugin
CVE-2026-81800 is an unauthenticated SQL injection flaw (CWE-89) in the Verified Reviews (Avis Vérifiés) WordPress plugin, affecting all versions up to and including 2.4.6. Because the vulnerable code path requires no authentication (CVSS AV:N/PR:N/UI:N), a remote attacker can send crafted input — for example, a parameter handled by the plugin in a database query — and inject malicious SQL into the site's database. The published CVSS (C:H, I:N, A:L, scope changed) indicates the primary impact is high-confidentiality disclosure of database contents, with limited availability impact and no direct integrity impact; in practice this could expose data such as plugin-managed review/order data, WordPress user records and password hashes, and other tables in the database. Any WordPress site running the plugin at version 2.4.6 or earlier is affected. The issue was disclosed through Patchstack (the assigned CNA); it is not in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation is currently known.
What to do: Update the Verified Reviews (Avis Vérifiés) plugin on every affected site to the latest patched release (any version above 2.4.6, e.g., 2.4.7 or later once published). Until patched, consider deactivating the plugin or applying WAF rules that block SQL-injection patterns against the plugin's endpoints, and review web logs for suspicious unauthenticated requests to plugin routes. Since no public PoC exists, prioritize internet-exposed WordPress sites running the plugin.
| Netreviews (Verified Reviews / Avis Vérifiés) Verified Reviews (Avis Vérifiés) WordPress plugin | <= 2.4.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.