VendorsGoldpluginseasy_testimonialsall versions
Vulnerabilities

Goldplugins Gold Plugins Easy Testimonials

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-2337
Easy Testimonials <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-07-20 · Analyzed
6.4EPSS 0.004
CVE-2018-19564
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
Published 2018-11-26 · Modified
6.1EPSS 0.009
CVE-2017-12131
The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.
Published 2017-08-01 · Modified
6.1EPSS 0.008
CVE-2020-14959
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, Item Reviewed, or Rating parameter.
Published 2020-06-21 · Modified
5.4EPSS 0.009
CVE-2022-4577
Easy Testimonials < 3.9.3 - Contributor+ Stored XSS
Published 2023-02-06 · Modified
5.4EPSS 0.006
CVE-2020-36749
Easy Testimonials <= 3.6.1 - Cross-Site Request Forgery Bypass
Published 2023-07-01 · Modified
4.3EPSS 0.005