The plugin does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed
As admin, create/edit a testimonial and put the following payload in the Testimonial User Name field: " style=animation-name:rotation onanimationstart=alert(/XSS/)//
CPE | Name | Operator | Version |
---|---|---|---|
testimonial-builder | lt | 1.6.0 |