Cross-Site Request Forgery in Plumeria Web Design Web Testimonials
CVE-2025-23560
7.1HIGH
What is CVE-2025-23560?
A Cross-Site Request Forgery (CSRF) vulnerability exists in Plumeria Web Design's Web Testimonials plugin, which can lead to Stored XSS vulnerabilities. This flaw occurs in versions up to and including 1.2 and allows unauthorized commands to be transmitted from a user’s browser without their consent, potentially resulting in the execution of malicious scripts. Website administrators using this plugin should take immediate action to secure their installations.
Affected Version(s)
Web Testimonials <= 1.2