Show filters
56 Total Results
Displaying 21-30 of 56
Sort by:
Attacker Value
Unknown
CVE-2024-38345
Disclosure Date: July 04, 2024 (last updated July 04, 2024)
A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.
0
Attacker Value
Unknown
CVE-2023-6491
Disclosure Date: June 07, 2024 (last updated October 30, 2024)
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.
0
Attacker Value
Unknown
CVE-2024-4705
Disclosure Date: June 06, 2024 (last updated November 21, 2024)
The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-3261
Disclosure Date: April 24, 2024 (last updated April 24, 2024)
The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed
0
Attacker Value
Unknown
CVE-2024-32530
Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Testimonials Showcase allows Stored XSS.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5.
0
Attacker Value
Unknown
CVE-2024-31348
Disclosure Date: April 07, 2024 (last updated April 10, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testimonials allows Stored XSS.This issue affects Testimonials: from n/a through 3.0.5.
0
Attacker Value
Unknown
CVE-2024-25924
Disclosure Date: March 28, 2024 (last updated April 02, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.
0
Attacker Value
Unknown
CVE-2023-52123
Disclosure Date: January 05, 2024 (last updated October 30, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.
0
Attacker Value
Unknown
CVE-2023-48283
Disclosure Date: November 30, 2023 (last updated December 05, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Testimonials Showcase allows Cross Site Request Forgery.This issue affects Simple Testimonials Showcase: from n/a through 1.1.5.
0
Attacker Value
Unknown
CVE-2023-5613
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0