cleantalk
Vulnerabilities and Security Researches

Strong Testimonials, CVE-2024-3261

CVE, Research URL

CVE-2024-3261

Application

Strong Testimonials

Published on
Apr 24, 2024
Research Description
The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed
Affected versions
Min -, max 3.1.12.
Status
vulnerable