Elegant Testimonial [wp-elegant-testimonial] < 1.1.7
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by Melbin K Mathew in WordPress Elegant Testimonial plugin (versions <= 1.1.6).
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Aug 19, 2020
WP Elegant Testimonial <= 1.1.6 - Cross-Site Scripting
high
The WP Elegant Testimonial plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2020
Elegant Testimonial [wp-elegant-testimonial] <= 1.1.6 (unfixed)
unknown
The WP Elegant Testimonial plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2020
Elegant Testimonial [wp-elegant-testimonial] <= 1.1.6 (unfixed + closed)
unknown
The name, company and text fields used while adding a testimonial to a page was found to be vulnerable to stored XSS, as they did not sanitize user given input properly before publishing the post. It is triggered when a user loads a page where the plugin shortcode is used. All WordPress websites using WP Elegant Testim...
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database