Extension WordPress

Vulnérabilités Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Cette page rassemble les failles publiées pour Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

6 fiches

CVE-2024-13704 Élevée · 7,2
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Super Testimonials <= 4.0.1 – Unauthenticated Stored Cross-Site Scripting

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-4.0.1

Correctif

4.0.2

Publication

17/02/2025

CVE-2024-43959 Moyenne · 6,1
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Testimonials <= 3.0.8 – Reflected Cross-Site Scripting

The Testimonials plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

26/08/2024

CVE-2024-31348 Moyenne · 6,4
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Testimonials <= 3.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-3.0.5

Correctif

3.0.6

Publication

05/04/2024

CVE-2023-5613 Moyenne · 6,4
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Super Testimonials <= 2.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-2.9

Correctif

3.0

Publication

16/10/2023

CVE-2021-36858 Moyenne · 5,5
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Testimonials <= 2.6 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…

Versions affectées

*-2.6

Correctif

2.7

Publication

27/10/2022

CVE-2022-3539 Moyenne · 5,5
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress

Testimonials (Free <= 2.6, Pro < 1.0.7) – Authenticated (Administrator+) Stored Cross-Site Scripting

The Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter in versions up to, and including, 2.6 (Free) and 1.0.7 (Pro) due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.6

Correctif

2.7

Publication

20/10/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités