plugin

Testimonial Rotator Vulnerabilities

5 known security issues reported for the Testimonial Rotator WordPress plugin. Most recent disclosed Apr 5, 2021.

2 medium

Running Testimonial Rotator on your site? Check whether your installed version is affected.

Scan your site free

Testimonial Rotator [testimonial-rotator] <= 3.0.3 (unfixed + closed)

unknown

[en] Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation

Affected:
up to 3.0.3
Fix:
No patched version reported
Disclosed:
Apr 5, 2021

CVE-2021-24156 on NVD →

Testimonial Rotator <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation

CVSS:
6.4
Affected:
up to 3.0.3
Fix:
No patched version reported
Disclosed:
Feb 19, 2021

CVE-2021-24156 on NVD →

Testimonial Rotator [testimonial-rotator] <= 3.0.3 (unfixed + closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Nguyen Anh Tien in WordPress Testimonial Rotator (versions <= 3.0.3).

Affected:
up to 3.0.3
Fix:
No patched version reported
Disclosed:
Feb 19, 2021

Testimonial Rotator [testimonial-rotator] < 3.0.3 (closed)

unknown

[en] Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Oct 16, 2020

CVE-2020-26672 on NVD →

Testimonial Rotator <= 3.0.2 - Authenticated Stored Cross-Site Scripting

medium

Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

CVSS:
6.4
Affected:
up to 3.0.3
Fix:
No patched version reported
Disclosed:
Jun 17, 2020

CVE-2020-26672 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database