Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode
medium
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 3.2.21
- Fixed in:
- 3.2.22
- Disclosed:
- Apr 7, 2026
CVE-2026-3239 on NVD →
Strong Testimonials [strong-testimonials] <= 3.2.20 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20.
- Affected:
- up to 3.2.20
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24957 on NVD →
Strong Testimonials [strong-testimonials] < 3.2.19
unknown
[en] The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delet...
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.19
- Disclosed:
- Dec 30, 2025
CVE-2025-14426 on NVD →
Strong Testimonials <= 3.2.18 - Missing Authorization to Authenticated (Contributor+) Rating Meta Update
medium
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delete the...
- CVSS:
- 4.3
- Affected:
- up to 3.2.18
- Fixed in:
- 3.2.19
- Disclosed:
- Dec 29, 2025
CVE-2025-14426 on NVD →
Strong Testimonials <= 3.2.20 - Missing Authorization
medium
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.20. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.2.20
- Fixed in:
- 3.2.21
- Disclosed:
- Dec 28, 2025
CVE-2026-24957 on NVD →
Strong Testimonials [strong-testimonials] < 3.2.17
unknown
[en] The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This mak...
- Affected:
- up to 3.2.17
- Fixed in:
- 3.2.17
- Disclosed:
- Nov 6, 2025
CVE-2025-11268 on NVD →
Strong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode Execution
medium
The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.17
- Disclosed:
- Nov 5, 2025
CVE-2025-11268 on NVD →
Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields
medium
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.12
- Disclosed:
- Jul 14, 2025
CVE-2025-7367 on NVD →
Strong Testimonials [strong-testimonials] < 3.2.4
unknown
[en] Missing Authorization vulnerability in WP Chill Strong Testimonials allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Strong Testimonials: from n/a through 3.2.3.
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.4
- Disclosed:
- Feb 25, 2025
CVE-2025-26975 on NVD →
Strong Testimonials <= 3.2.3 - Missing Authorization
medium
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.4
- Disclosed:
- Feb 23, 2025
CVE-2025-26975 on NVD →
Strong Testimonials [strong-testimonials] < 3.1.17
unknown
[en] Missing Authorization vulnerability in WPChill Strong Testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through 3.1.16.
- Affected:
- up to 3.1.17
- Fixed in:
- 3.1.17
- Disclosed:
- Nov 1, 2024
CVE-2024-47362 on NVD →
Strong Testimonials <= 3.1.16 - Missing Authorization
medium
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.1.16
- Fixed in:
- 3.1.17
- Disclosed:
- Sep 30, 2024
CVE-2024-47362 on NVD →
Strong Testimonials [strong-testimonials] < 3.1.13
unknown
[en] The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify...
- Affected:
- up to 3.1.13
- Fixed in:
- 3.1.13
- Disclosed:
- Jun 7, 2024
CVE-2023-6491 on NVD →
Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modification
medium
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favor...
- CVSS:
- 4.3
- Affected:
- up to 3.1.12
- Fixed in:
- 3.1.13
- Disclosed:
- Jun 6, 2024
CVE-2023-6491 on NVD →
Strong Testimonials [strong-testimonials] < 3.1.12
unknown
[en] The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be perfor...
- Affected:
- up to 3.1.12
- Fixed in:
- 3.1.12
- Disclosed:
- Apr 24, 2024
CVE-2024-3261 on NVD →
Strong Testimonials <= 3.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Full Name field parameter in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to i...
- CVSS:
- 6.4
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.12
- Disclosed:
- Apr 3, 2024
CVE-2024-3261 on NVD →
Strong Testimonials [strong-testimonials] < 3.1.11
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.11
- Disclosed:
- Jan 5, 2024
CVE-2023-52123 on NVD →
Strong Testimonials <= 3.1.10 - Cross-Site Request Forgery
medium
The Strong Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.10. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke them via a forged request granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 3.1.10
- Fixed in:
- 3.1.11
- Disclosed:
- Dec 28, 2023
CVE-2023-52123 on NVD →
Strong Testimonials [strong-testimonials] < 3.0.3
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Jun 16, 2023
CVE-2023-26013 on NVD →
Strong Testimonials <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
medium
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-leve...
- CVSS:
- 6.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 21, 2023
CVE-2023-26013 on NVD →
Strong Testimonials [strong-testimonials] < 3.0.3
unknown
[en] The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such...
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Feb 6, 2023
CVE-2022-4717 on NVD →
Strong Testimonials <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level...
- CVSS:
- 6.4
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Jan 10, 2023
CVE-2022-4717 on NVD →
Strong Testimonials <= 2.51.2 - Authorization Bypass
high
The Strong Testimonials plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpmtst_ajax_cat_count function and wpmtst_add_field_* functions in versions up to, and including, 2.51.2. This makes it possible for authenticated attackers, with subscriber-level permissions and...
- CVSS:
- 7.5
- Affected:
- up to 2.51.2
- Fixed in:
- 2.51.3
- Disclosed:
- Jun 30, 2021
Strong Testimonials [strong-testimonials] < 2.51.3
unknown
The Strong Testimonials plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpmtst_ajax_cat_count function and wpmtst_add_field_* functions in versions up to, and including, 2.51.2. This makes it possible for authenticated attackers, with subscriber-level permissions and...
- Affected:
- up to 2.51.3
- Fixed in:
- 2.51.3
- Disclosed:
- Jun 30, 2021
Strong Testimonials [strong-testimonials] < 2.40.1
unknown
[en] Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
- Affected:
- up to 2.40.1
- Fixed in:
- 2.40.1
- Disclosed:
- Feb 3, 2020
CVE-2020-8549 on NVD →
Strong Testimonials <= 2.40.0 - Stored Cross Site Scripting
medium
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
- CVSS:
- 6.1
- Affected:
- up to 2.40.0
- Fixed in:
- 2.40.1
- Disclosed:
- Feb 1, 2020
CVE-2020-8549 on NVD →
Strong Testimonials [strong-testimonials] < 2.40.1
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Jinson Varghese Behanan in WordPress Strong Testimonials plugin (versions <= 2.40.0).
- Affected:
- up to 2.40.1
- Fixed in:
- 2.40.1
- Disclosed:
- Feb 1, 2020
Strong Testimonials [strong-testimonials] < 2.31.5
unknown
Multiple Authenticated Cross-Site Scripting (XSS) vulnerabilities found by DefenseCode in WordPress Strong Testimonials plugin (versions <= 2.31.4).
- Affected:
- up to 2.31.5
- Fixed in:
- 2.31.5
- Disclosed:
- Aug 9, 2018
Strong Testimonials <= 2.31.4 - Reflected Cross-Site Scripting
medium
The Strong Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 2.31.4
- Fixed in:
- 2.31.5
- Disclosed:
- Jul 24, 2018
Strong Testimonials [strong-testimonials] < 2.31.5
unknown
The Strong Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- Affected:
- up to 2.31.5
- Fixed in:
- 2.31.5
- Disclosed:
- Jul 24, 2018
Strong Testimonials [strong-testimonials] < 2.51.3
unknown
The plugin did not propely check for CSRF and authorisation in all the wpmtst_add_field_*_function functions, allowing unauthorised call of the associated AJAX actions either via low privilege users or CSRF attack
- Affected:
- up to 2.51.3
- Fixed in:
- 2.51.3
Strong Testimonials [strong-testimonials] < 2.31.5
unknown
The Strong Testimonials WordPress plugin was affected by a Multiple Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.31.5
- Fixed in:
- 2.31.5
Strong Testimonials [strong-testimonials] < 3.2.12
unknown
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.12
CVE-2025-7367 on NVD →