Strong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode
Strong Testimonials
Minimum safe version
3.2.22
Update to 3.2.22 or later to address 19 fixable vulnerabilities
CVE-2026-24957
CVE-2025-14426
CVE-2025-11268
Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields
CVE-2025-26975
CVE-2024-47362
CVE-2023-6491
CVE-2024-3261
WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)
Strong Testimonials < 2.51.3 - Unauthorised AJAX Call
Strong Testimonials <= 2.31.4 - Multiple Authenticated Cross-Site Scripting (XSS)
CVE-2023-26013
CVE-2022-4717
Strong Testimonials <= 2.31.4 - Reflected Cross-Site Scripting
Strong Testimonials <= 2.51.2 - Authorization Bypass
WordPress Strong Testimonials plugin <= 2.31.4 - Multiple Authenticated Cross-Site Scripting (XSS) vulnerabilities
WordPress Strong Testimonials plugin <= 2.40.0 - Stored Cross Site Scripting (XSS) vulnerability
CVE-2020-8549