Goldplugins

Easy Testimonials

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 20.07.2024 03:15:02
  • Zuletzt bearbeitet 10.07.2025 18:23:02

The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user sup...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 01.07.2023 06:15:09
  • Zuletzt bearbeitet 21.11.2024 05:30:13

The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauth...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 06.02.2023 20:15:11
  • Zuletzt bearbeitet 26.03.2025 14:15:25

The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 22.06.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 05:04:31

Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Review...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 26.11.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:11

Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 01.08.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.