Testimonial Rotator [testimonial-rotator] <= 3.0.3 (unfixed + closed)
unknown
[en] Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
- Affected:
- up to 3.0.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 5, 2021
CVE-2021-24156 on NVD →
Testimonial Rotator <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
- CVSS:
- 6.4
- Affected:
- up to 3.0.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2021
CVE-2021-24156 on NVD →
Testimonial Rotator [testimonial-rotator] <= 3.0.3 (unfixed + closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Nguyen Anh Tien in WordPress Testimonial Rotator (versions <= 3.0.3).
- Affected:
- up to 3.0.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2021
Testimonial Rotator [testimonial-rotator] < 3.0.3 (closed)
unknown
[en] Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Oct 16, 2020
CVE-2020-26672 on NVD →
Testimonial Rotator <= 3.0.2 - Authenticated Stored Cross-Site Scripting
medium
Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.
- CVSS:
- 6.4
- Affected:
- up to 3.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 17, 2020
CVE-2020-26672 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database