plugin

Ap Custom Testimonial Vulnerabilities

5 known security issues reported for the Ap Custom Testimonial WordPress plugin. Most recent disclosed Feb 28, 2022.

1 high 1 medium

Running Ap Custom Testimonial on your site? Check whether your installed version is affected.

Scan your site free

Testimonial WordPress Plugin &#8211; AP Custom Testimonial [ap-custom-testimonial] < 1.4.8 (closed)

unknown

[en] The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Feb 28, 2022

CVE-2022-23911 on NVD →

Testimonial WordPress Plugin &#8211; AP Custom Testimonial [ap-custom-testimonial] < 1.4.8 (closed)

unknown

[en] The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting

Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Feb 28, 2022

CVE-2022-23912 on NVD →

Testimonial WordPress Plugin &#8211; AP Custom Testimonial [ap-custom-testimonial] < 1.4.7 (closed)

unknown

[en] Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confus...

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Feb 21, 2022

CVE-2021-24867 on NVD →

AP Custom Testimonial <= 1.4.7 - SQL Injection

high

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

CVSS:
7.2
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Jan 25, 2022

CVE-2022-23911 on NVD →

Testimonial WordPress Plugin < 1.4.7 - Reflected Cross-Site Scripting

medium

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting.

CVSS:
6.1
Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Jan 25, 2022

CVE-2022-23912 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database