Lucene search

K

Strong Testimonials Security Vulnerabilities

cve
cve

CVE-2022-4717

The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high priv...

5.4CVSS

5.3AI Score

0.001EPSS

2023-02-06 08:15 PM
26
cve
cve

CVE-2023-26013

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions.

6.5CVSS

5.2AI Score

0.0005EPSS

2023-06-16 09:15 AM
23
cve
cve

CVE-2023-6491

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and a...

4.3CVSS

6.7AI Score

0.0004EPSS

2024-06-07 06:15 AM
24
cve
cve

CVE-2024-3261

The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific v...

4.8CVSS

8AI Score

0.0004EPSS

2024-04-24 05:15 AM
40