Testimonial Carousel For Elementor <= 11.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and ab...
- CVSS:
- 6.4
- Affected:
- up to 11.6.2
- Fixed in:
- 11.7.0
- Disclosed:
- Oct 24, 2025
CVE-2025-8666 on NVD →
Testimonial Carousel For Elementor [testimonials-carousel-elementor] < 10.2.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UAPP GROUP Testimonial Carousel For Elementor allows Stored XSS.This issue affects Testimonial Carousel For Elementor: from n/a through 10.1.1.
- Affected:
- up to 10.2.0
- Fixed in:
- 10.2.0
- Disclosed:
- Jun 8, 2024
CVE-2024-35713 on NVD →
Testimonial Carousel For Elementor [testimonials-carousel-elementor] < 10.2.3
unknown
[en] The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...
- Affected:
- up to 10.2.3
- Fixed in:
- 10.2.3
- Disclosed:
- May 30, 2024
CVE-2024-2253 on NVD →
Testimonial Carousel For Elementor <= 10.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and including, 10.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- CVSS:
- 6.4
- Affected:
- up to 10.2.2
- Fixed in:
- 10.2.3
- Disclosed:
- May 29, 2024
CVE-2024-2253 on NVD →
Testimonial Carousel For Elementor [testimonials-carousel-elementor] < 10.2.1
unknown
[en] The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI AP...
- Affected:
- up to 10.2.1
- Fixed in:
- 10.2.1
- Disclosed:
- May 25, 2024
CVE-2024-4858 on NVD →
Testimonial Carousel For Elementor <= 10.2.0 - Missing Authorization to Limited Setting Update
medium
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI API key...
- CVSS:
- 5.3
- Affected:
- up to 10.2.0
- Fixed in:
- 10.2.1
- Disclosed:
- May 24, 2024
CVE-2024-4858 on NVD →
Testimonial Carousel For Elementor [testimonials-carousel-elementor] < 10.2.0
unknown
[en] The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- Affected:
- up to 10.2.0
- Fixed in:
- 10.2.0
- Disclosed:
- May 18, 2024
CVE-2024-4698 on NVD →
Testimonial Carousel For Elementor <= 10.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 10.1.1
- Fixed in:
- 10.2.0
- Disclosed:
- May 17, 2024
CVE-2024-4698 on NVD →
Testimonial Carousel For Elementor [testimonials-carousel-elementor] < 11.7.0
unknown
- Affected:
- up to 11.7.0
- Fixed in:
- 11.7.0
CVE-2025-8666 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database