Easy Testimonials [easy-testimonials] <= 3.9.5 (unfixed + closed)
unknown
[en] The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- Affected:
- up to 3.9.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 20, 2024
CVE-2024-2337 on NVD →
Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_grid ' shortcode in all versions up to, and including, 3.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers w...
- CVSS:
- 6.4
- Affected:
- up to 3.9.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 19, 2024
CVE-2024-2337 on NVD →
Easy Testimonials [easy-testimonials] < 3.7 (closed)
unknown
[en] The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request gr...
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jul 1, 2023
CVE-2020-36749 on NVD →
Easy Testimonials [easy-testimonials] < 3.7 (closed)
unknown
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Easy Testimonials [easy-testimonials] < 3.9.3 (closed)
unknown
[en] The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such a...
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Feb 6, 2023
CVE-2022-4577 on NVD →
Easy Testimonials <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level an...
- CVSS:
- 6.4
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.3
- Disclosed:
- Jan 10, 2023
CVE-2022-4577 on NVD →
Easy Testimonials <= 3.8 - Reflected Cross-Site Scripting
medium
The plugin Easy Testimonials for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 3.8
- Fixed in:
- 3.9
- Disclosed:
- Jun 14, 2022
Easy Testimonials [easy-testimonials] < 3.9 (closed)
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Easy Testimonials plugin (versions <= 3.8).
Update the WordPress Easy Testimonials plugin to the latest available version (at least 3.9).
- Affected:
- up to 3.9
- Fixed in:
- 3.9
- Disclosed:
- Jun 14, 2022
Easy Testimonials [easy-testimonials] < 3.8 (closed)
unknown
The plugin Easy Testimonials for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- Jun 14, 2022
Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypass
medium
The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Sep 16, 2020
CVE-2020-36749 on NVD →
Easy Testimonials [easy-testimonials] < 3.7 (closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Easy Testimonials plugin (versions <= 3.6.1).
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Sep 16, 2020
Easy Testimonials [easy-testimonials] < 3.6 (closed)
unknown
[en] Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Jun 21, 2020
CVE-2020-14959 on NVD →
Easy Testimonials <= 3.5.2 - Authenticated Stored Cross-Site Scripting
medium
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
- CVSS:
- 5.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.6
- Disclosed:
- May 13, 2020
CVE-2020-14959 on NVD →
Easy Testimonials <= 3.5.2 - Stored Cross-Site Scripting
medium
Stored XSS was discovered in the Easy Testimonials plugin 3.5.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
- CVSS:
- 6.1
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Nov 26, 2018
CVE-2018-19564 on NVD →
Easy Testimonials [easy-testimonials] < 3.6 (closed)
unknown
[en] Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Nov 26, 2018
CVE-2018-19564 on NVD →
Easy Testimonials <= 3.0.4 - Cross-Site Scripting
medium
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.
- CVSS:
- 6.1
- Affected:
- up to 3.0.4
- Fix:
- No patched version reported
- Disclosed:
- Jul 31, 2017
CVE-2017-12131 on NVD →
Easy Testimonials <= 1.36.1 - Authenticated Stored Cross-Site Scripting
high
The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.36.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of the Contributor-level or above to inject arbitrary web...
- CVSS:
- 7.4
- Affected:
- up to 1.37
- Fixed in:
- 1.37
- Disclosed:
- Jul 31, 2016
Easy Testimonials [easy-testimonials] < 1.37 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 1.37
- Fixed in:
- 1.37
- Disclosed:
- Jul 31, 2016
Easy Testimonials [easy-testimonials] < 1.37 (closed)
unknown
The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.36.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers of the Contributor-level or above to inject arbitrary web...
- Affected:
- up to 1.37
- Fixed in:
- 1.37
- Disclosed:
- Jul 31, 2016
Easy Testimonials [easy-testimonials] < 3.7 (closed)
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 3.7
- Fixed in:
- 3.7
Easy Testimonials [easy-testimonials] < 3.9 (closed)
unknown
The plugin, when used along the Pro version, does not escape an URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting
- Affected:
- up to 3.9
- Fixed in:
- 3.9
Easy Testimonials [easy-testimonials] < 1.37 (closed)
unknown
Multiple stored Cross-Site Scripting vulnerabilities were found and can be exploited by an authenticated Contributor (or higher).
- Affected:
- up to 1.37
- Fixed in:
- 1.37
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database