Extension WordPress
Vulnérabilités Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
Cette page rassemble les failles publiées pour Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
8 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-3.2.8
3.2.9
30/04/2026
GS Testimonial Slider <= 3.3.0 – Missing Authorization
The GS Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_shortcode_pref() function in versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with subscriber-level…
*-3.3.0
3.3.1
07/05/2025
GS Testimonial Slider <= 3.2.9 – Unauthenticated Arbitrary Shortcode Execution
The The A WordPress Testimonial Plugin to Showcase Testimonial Slider, Testimonial Grid and More: Solid Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.9. This is due to the…
*-3.2.9
3.3.0
07/05/2025
GS Testimonial Slider <= 3.1.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-3.1.4
3.1.5
28/03/2024
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-1.9.7
1.9.8
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-1.9.7
1.9.8
14/12/2022
GS Testimonial Slider <= 1.9.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.9.6
1.9.7
15/09/2022
GS Testimonial Slider <= 1.9.6 – Authenticated (Author+) Stored Cross-Site Scripting
The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as 'gs_t_client_company' and 'gs_t_client_design' in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes…
*-1.9.6
1.9.7
27/07/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.