CVE-2026-96650
- EPSS 0.26%
- Veröffentlicht 03.10.2026 05:29:15
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it po...
CVE-2026-97286
- EPSS 0.15%
- Veröffentlicht 30.09.2026 12:28:18
- Zuletzt bearbeitet 02.10.2026 18:17:09
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11.
CVE-2026-92622
- EPSS 0.24%
- Veröffentlicht 18.09.2026 07:40:00
- Zuletzt bearbeitet 18.09.2026 20:17:29
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it p...
CVE-2026-3239
- EPSS 0.2%
- Veröffentlicht 08.04.2026 04:27:16
- Zuletzt bearbeitet 25.07.2026 10:10:00
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supp...
CVE-2026-24957
- EPSS 0.25%
- Veröffentlicht 03.02.2026 14:08:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20.
CVE-2025-14426
- EPSS 0.21%
- Veröffentlicht 30.12.2025 12:22:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated att...
CVE-2025-11268
- EPSS 0.27%
- Veröffentlicht 06.11.2025 08:26:27
- Zuletzt bearbeitet 07.10.2026 21:10:00
The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or...
CVE-2025-7367
- EPSS 0.22%
- Veröffentlicht 15.07.2025 04:23:41
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possibl...
CVE-2025-26975
- EPSS 0.37%
- Veröffentlicht 25.02.2025 15:15:30
- Zuletzt bearbeitet 23.04.2026 15:26:10
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3.
CVE-2024-47362
- EPSS 0.4%
- Veröffentlicht 01.11.2024 15:15:55
- Zuletzt bearbeitet 23.04.2026 15:19:14
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16.