Stored Cross-Site Scripting Vulnerability in Testimonial Slider and Showcase Plugin by WordPress
CVE-2022-50947
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 May 2026
Badges
What is CVE-2022-50947?
The Testimonial Slider and Showcase Plugin version 2.2.6 for WordPress contains a stored cross-site scripting vulnerability. This flaw allows authenticated users with editor privileges to inject malicious JavaScript into the testimonial title field, which subsequently executes in the browsers of users viewing the draft posts. As a result, attackers can exploit this vulnerability to steal cookies and hijack sessions, posing a significant risk to web applications that rely on this plugin.
Affected Version(s)
Testimonial Slider and Showcase 2.2.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved