Stored Cross-Site Scripting in Strong Testimonials Plugin for WordPress
CVE-2026-3239

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-3239?

The Strong Testimonials plugin for WordPress contains a vulnerability that allows for stored cross-site scripting (XSS) attacks through its testimonial_view shortcode. This flaw, present in all versions up to and including 3.2.21, arises from inadequate input sanitization and output escaping of user-supplied attributes. As a result, authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages, leading to potential exploitations whenever affected pages are accessed. It is crucial for users and administrators to be aware of this vulnerability and apply necessary updates to maintain site security.

Affected Version(s)

Strong Testimonials 0 <= 3.2.21

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ronnachai Sretawat Na Ayutaya
.