Back

MEDIUM

Strong Testimonials < 3.1.12 - Contributor+ Stored XSS

Published Apr 24, 2024

Description

The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 24, 2024
Updated Aug 1, 2024
Reserved Apr 3, 2024
CISA Vulnrichment
Updated Jul 26, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a