Show filters
56 Total Results
Displaying 41-50 of 56
Sort by:
Attacker Value
Unknown

CVE-2022-4648

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-3539

Disclosure Date: November 14, 2022 (last updated December 22, 2024)
The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-36858

Disclosure Date: October 27, 2022 (last updated December 22, 2024)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
Attacker Value
Unknown

CVE-2022-33191

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress.
Attacker Value
Unknown

CVE-2021-24492

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
Attacker Value
Unknown

CVE-2021-24136

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
Attacker Value
Unknown

CVE-2020-14959

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
Attacker Value
Unknown

CVE-2020-8549

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
Attacker Value
Unknown

CVE-2013-4241

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).
Attacker Value
Unknown

CVE-2017-18558

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
0