Strong Testimonials, CVE-2025-11268
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 06, 2025
- Research Description
- The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes if an administrator previews or publishes a crafted testimonial.
- Affected versions
-
max 3.2.17.
- Status
-
vulnerable