Stored Cross-Site Scripting Vulnerability in Testimonial Post Type Plugin for WordPress
CVE-2025-5800
6.4MEDIUM
What is CVE-2025-5800?
The Testimonial Post Type plugin for WordPress is susceptible to a stored cross-site scripting vulnerability through the 'auto_play' parameter. This weakness stems from inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access or higher to inject malicious web scripts. These scripts can execute automatically when users visit the compromised pages, posing a significant risk to the integrity of the web application and user data.
Affected Version(s)
Testimonial Post type * <= 1.2.1