Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-46799

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions.
Attacker Value
Unknown

CVE-2022-44741

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
Attacker Value
Unknown

CVE-2022-40213

Disclosure Date: September 14, 2022 (last updated October 08, 2023)
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.
Attacker Value
Unknown

CVE-2022-35882

Disclosure Date: July 27, 2022 (last updated November 29, 2024)
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.5 at WordPress.
Attacker Value
Unknown

CVE-2021-36851

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated October 07, 2023)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2015-9417

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
Attacker Value
Unknown

CVE-2018-5372

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
0