CVE-2024-2337
- EPSS 0.16%
- Veröffentlicht 20.07.2024 03:15:02
- Zuletzt bearbeitet 10.07.2025 18:23:02
The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user sup...
CVE-2020-36749
- EPSS 0.09%
- Veröffentlicht 01.07.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 05:30:13
The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauth...
CVE-2022-4577
- EPSS 0.25%
- Veröffentlicht 06.02.2023 20:15:11
- Zuletzt bearbeitet 26.03.2025 14:15:25
The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin...
CVE-2020-14959
- EPSS 0.16%
- Veröffentlicht 22.06.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:31
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Review...
CVE-2018-19564
- EPSS 0.17%
- Veröffentlicht 26.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:11
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
CVE-2017-12131
- EPSS 0.32%
- Veröffentlicht 01.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.