Ljapps develops a suite of WordPress plugins for displaying customer reviews across multiple platforms, including Google, Airbnb, TripAdvisor, and Yelp integrations. The vendor's vulnerability profile centers on web application input-handling issues, with recurring exposure through cross-site scripting, cross-site request forgery, and SQL injection flaws typical of plugin ecosystems where form parsing and database interaction occur at scale. Public exploit code has a moderate tendency to emerge for this vendor's disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ljapps over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0261HIGH The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection explo | Feb 13, 2023 | 8.8 | 39 | NO | YES |
CVE-2023-23890HIGH Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions. | May 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-0262HIGH The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable | Feb 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-0259HIGH The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitabl | Feb 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-0263HIGH The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable b | Feb 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-0260HIGH The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by us | Feb 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-0383HIGH The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform | Feb 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-35630HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue aff | Jun 3, 2024 | 7.6 | 23 | NO | NO |
CVE-2024-2310MEDIUM The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Apr 26, 2024 | 5.9 | 20 | NO | NO |
CVE-2022-4242MEDIUM The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Dec 26, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ljapps.
Media articles that mention a CVE ID that affects a product developed by Ljapps — matched by CVE ID, not by vendor name.