Missing Authorization Vulnerability in Strong Testimonials Plugin by WordPress
CVE-2025-26975

5.3MEDIUM

Key Information:

Vendor
WP Chill
Status
Strong Testimonials
Vendor
CVE Published:
25 February 2025

Summary

The Strong Testimonials plugin for WordPress is affected by a missing authorization vulnerability, which enables unauthorized access to functionality that is not properly constrained by access control lists (ACLs). This issue poses a significant risk, as it allows attackers to exploit the plugin across various versions, including 3.2.3. Users of the affected plugin are advised to implement necessary security measures to mitigate potential threats.

Affected Version(s)

Strong Testimonials <= 3.2.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Revan Arifio (Patchstack Alliance)
.