ZeroHour

CVE-2026-81800

moderate

Unauthenticated SQL Injection in WordPress Verified Reviews (Avis Vérifiés) Plugin

CVSS 3.1
9.3 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-81800 is an unauthenticated SQL injection flaw (CWE-89) in the Verified Reviews (Avis Vérifiés) WordPress plugin, affecting all versions up to and including 2.4.6. Because the vulnerable code path requires no authentication (CVSS AV:N/PR:N/UI:N), a remote attacker can send crafted input — for example, a parameter handled by the plugin in a database query — and inject malicious SQL into the site's database. The published CVSS (C:H, I:N, A:L, scope changed) indicates the primary impact is high-confidentiality disclosure of database contents, with limited availability impact and no direct integrity impact; in practice this could expose data such as plugin-managed review/order data, WordPress user records and password hashes, and other tables in the database. Any WordPress site running the plugin at version 2.4.6 or earlier is affected. The issue was disclosed through Patchstack (the assigned CNA); it is not in CISA's KEV catalog and no public proof-of-concept or confirmed in-the-wild exploitation is currently known.

What to do: Update the Verified Reviews (Avis Vérifiés) plugin on every affected site to the latest patched release (any version above 2.4.6, e.g., 2.4.7 or later once published). Until patched, consider deactivating the plugin or applying WAF rules that block SQL-injection patterns against the plugin's endpoints, and review web logs for suspicious unauthenticated requests to plugin routes. Since no public PoC exists, prioritize internet-exposed WordPress sites running the plugin.

Affected
Netreviews (Verified Reviews / Avis Vérifiés) Verified Reviews (Avis Vérifiés) WordPress plugin<= 2.4.6
Estimated exposure
moderateroughly 10,000+ WordPress sites (low tens of thousands at most; exact count not in the source data) — No active-install counts were provided in the source data; the estimate is based on this plugin's profile as a niche French-market review-integration plugin in the WordPress plugin directory, which lists on the order of 10,000+ active…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.