Missing Authorization Vulnerability in Strong Testimonials Plugin by WordPress
CVE-2025-26975
5.3MEDIUM
Key Information:
- Vendor
- WP Chill
- Status
- Strong Testimonials
- Vendor
- CVE Published:
- 25 February 2025
Summary
The Strong Testimonials plugin for WordPress is affected by a missing authorization vulnerability, which enables unauthorized access to functionality that is not properly constrained by access control lists (ACLs). This issue poses a significant risk, as it allows attackers to exploit the plugin across various versions, including 3.2.3. Users of the affected plugin are advised to implement necessary security measures to mitigate potential threats.
Affected Version(s)
Strong Testimonials <= 3.2.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Revan Arifio (Patchstack Alliance)