cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortestimonial-free testimonial-free

Direction: ascending
Jun 07, 2024

Real Testimonials # de07c556153470bf804605a034dd1f6f42fc1f71

Application

Real Testimonials

Date
Mar 02, 2020
Research Description
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.2 WordPress Testimonial – Best Testimonial Slider plugin <= 2.1.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Testimonial – Best Testimonial Slider plugin (versions <= 2.1.7).
Affected versions
max 2.2.
Status
vulnerable

Real Testimonials # CVE-2022-4648

CVE, Research URL

CVE-2022-4648

Application

Real Testimonials

Date
Jan 16, 2023
Research Description
The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected versions
max 2.6.0.
Status
vulnerable
Apr 15, 2025

Real Testimonials # CVE-2025-22269

CVE, Research URL

CVE-2025-22269

Application

Real Testimonials

Date
Apr 16, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.
Affected versions
max 3.1.7.
Status
vulnerable
Jun 16, 2026

Real Testimonials # 8f1e70a958ba31272d3a21553ce89d5910ae5628

Application

Real Testimonials

Date
Feb 20, 2020
Research Description
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.2 Real Testimonials <= 2.1.6 - Authenticated Stored Cross-Site Scripting The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated low-privileged attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.2.
Status
vulnerable

Real Testimonials # b608d2d1-b757-427b-a079-32792c2a8d42

Application

Real Testimonials

Date
-
Research Description
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.1.7 Testimonial &lt; 2.2 - Authenticated Stored Cross-Site Scripting (XSS) A stored XSS vulnerability exists in the version of the plugin 2.1.6. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary javascript code into the plugin gallery image which is viewed by other users.
Affected versions
max 2.1.7.
Status
vulnerable