Unauthorized Data Modification in Strong Testimonials Plugin for WordPress
CVE-2025-14426
What is CVE-2025-14426?
The Strong Testimonials plugin for WordPress has a critical vulnerability due to a lack of capability checks in the 'edit_rating' function. This flaw permits authenticated users with Contributor-level access and above to manipulate or erase rating metadata associated with any testimonial post, including those created by other authors. By exploiting this vulnerability, attackers can use a valid nonce obtained from their testimonial edit interface to gain unauthorized control over testimonial ratings, compromising the integrity of the data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Strong Testimonials * <= 3.2.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved