Vulnerabilities and security researches fortestimonial-free testimonial-free
Direction: ascendingJun 07, 2024
Real Testimonials # de07c556153470bf804605a034dd1f6f42fc1f71
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 02, 2020
- Research Description
- Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.2 WordPress Testimonial – Best Testimonial Slider plugin <= 2.1.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Testimonial – Best Testimonial Slider plugin (versions <= 2.1.7).
- Affected versions
-
max 2.2.
- Status
-
vulnerable
Real Testimonials # CVE-2022-4648
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2023
- Research Description
- The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
- Affected versions
-
max 2.6.0.
- Status
-
vulnerable
Apr 15, 2025
Real Testimonials # CVE-2025-22269
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 16, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.
- Affected versions
-
max 3.1.7.
- Status
-
vulnerable
Jun 16, 2026
Real Testimonials # 8f1e70a958ba31272d3a21553ce89d5910ae5628
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 20, 2020
- Research Description
- Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.2 Real Testimonials <= 2.1.6 - Authenticated Stored Cross-Site Scripting The Real Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated low-privileged attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.2.
- Status
-
vulnerable
Real Testimonials # b608d2d1-b757-427b-a079-32792c2a8d42
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials [testimonial-free] < 2.1.7 Testimonial < 2.2 - Authenticated Stored Cross-Site Scripting (XSS) A stored XSS vulnerability exists in the version of the plugin 2.1.6. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary javascript code into the plugin gallery image which is viewed by other users.
- Affected versions
-
max 2.1.7.
- Status
-
vulnerable