Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
The Verified Reviews (Avis Vérifiés) plugin could let remote attackers access a website's database without logging in. They may be able to steal information stored there.
- Severity
- CriticalCVSS 3.1 · 9.3
- Fix
- Not confirmedLast checked today
- Affected versions
- through 2.4.6
- Weakness
- CWE-89SQL Injection
- Exploit likelihood
- 0.25% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- Verified Reviews (Avis Vérifiés)
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: partial
- EU ID
- EUVD-2026-75529ENISA vulnerability database
How it works
- An attacker can send database-related input to the plugin without providing login details.
- The plugin may then let that input interact directly with the site's database.
- This could expose information stored in that database.
What to do
Check the installed Verified Reviews (Avis Vérifiés) plugin version and compare it with the advisory's affected cutoff of 2.4.6.
Ask your hosting provider or web developer for help, and follow the Patchstack advisory.
Technical details
Affected software: Verified Reviews (Avis Vérifiés)WordPress plugin by Par avisverifies
CVE-2026-81800 affects the netreviews package through unauthenticated SQL injection. The CVE record rates it critical with a CVSS score of 9.3; Patchstack lists high priority and says attackers could interact directly with the database, including stealing information.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact None No data tampering
- Availability impact Low Reduced performance or interruptions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L Open in FIRST.org calculatorReferences
- tenable.com · CVE-2026-81800 third party advisory vdb entry
- patchstack.com · wordpress-verified-reviews-avis-verifies-plugin-2-4-6-sql-injection-vulnerability third party advisory technical description vdb-entry NVD
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-81800 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81800