Vulnerabilities > Machothemes > Strong Testimonials > 2.28.1

DATE CVE VULNERABILITY TITLE RISK
2024-01-05 CVE-2023-52123 Cross-Site Request Forgery (CSRF) vulnerability in Machothemes Strong Testimonials
Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10.
network
low complexity
machothemes CWE-352
8.8
2023-02-06 CVE-2022-4717 Unspecified vulnerability in Machothemes Strong Testimonials
The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
network
low complexity
machothemes
5.4
2020-02-03 CVE-2020-8549 Cross-site Scripting vulnerability in Machothemes Strong Testimonials
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
4.3