Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Goldplugins Subscribe
Filtered by product Easy Testimonials
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4577 1 Goldplugins 1 Easy Testimonials 2023-02-10 N/A 5.4 MEDIUM
The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2020-14959 1 Goldplugins 1 Easy Testimonials 2020-06-25 3.5 LOW 5.4 MEDIUM
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
CVE-2018-19564 1 Goldplugins 1 Easy Testimonials 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
CVE-2017-12131 1 Goldplugins 1 Easy Testimonials 2017-08-10 4.3 MEDIUM 6.1 MEDIUM
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.