cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches fortestimonials-carousel-elementor testimonials-carousel-elementor

Direction: descending
Nov 10, 2025

Testimonial Carousel For Elementor # CVE-2025-8666

CVE, Research URL

CVE-2025-8666

Date
Oct 25, 2025
Research Description
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 11.7.0.
Status
vulnerable
Jun 10, 2024

Testimonial Carousel For Elementor # CVE-2024-35713

CVE, Research URL

CVE-2024-35713

Date
Jun 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UAPP GROUP Testimonial Carousel For Elementor allows Stored XSS.This issue affects Testimonial Carousel For Elementor: from n/a through 10.1.1.
Affected versions
max 10.2.0.
Status
vulnerable
Jun 06, 2024

Testimonial Carousel For Elementor # CVE-2024-4698

CVE, Research URL

CVE-2024-4698

Date
May 18, 2024
Research Description
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.2.0.
Status
vulnerable

Testimonial Carousel For Elementor # CVE-2024-4858

CVE, Research URL

CVE-2024-4858

Date
May 25, 2024
Research Description
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI API key, disabling the feature.
Affected versions
max 10.2.1.
Status
vulnerable

Testimonial Carousel For Elementor # CVE-2024-2253

CVE, Research URL

CVE-2024-2253

Date
May 30, 2024
Research Description
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.2.3.
Status
vulnerable