Arbitrary Shortcode Execution Vulnerability in Strong Testimonials Plugin by WordPress
CVE-2025-11268
What is CVE-2025-11268?
The Strong Testimonials plugin for WordPress is susceptible to an arbitrary shortcode execution vulnerability. This issue arises from inadequate validation and sanitization of user-submitted testimonials, allowing unauthenticated attackers to introduce malicious shortcodes. If an administrator previews or publishes a crafted testimonial, this can result in unauthorized code being executed, posing significant risks to the site's integrity and security. Updating to the latest version is essential for mitigating this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Strong Testimonials * <= 3.2.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved