Stored Cross-Site Scripting Vulnerability in Strong Testimonials Plugin for WordPress
CVE-2026-92622

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

What is CVE-2026-92622?

The Strong Testimonials plugin for WordPress is exposed to a stored cross-site scripting vulnerability due to inadequate sanitization of input and insufficient output escaping via the 'lightbox_class' shortcode attribute. This vulnerability affects all versions up to and including 3.3.8. Attackers with contributor-level access or higher can exploit this issue to inject malicious web scripts into testimonials pages, which can execute when users access the compromised page. Exploitation occurs specifically when a testimonial view has a published testimonial with a featured image and the lightbox wrapper enabled, allowing the attack to be triggered during thumbnail rendering.

Affected Version(s)

Strong Testimonials 0 <= 3.3.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pb>sec
.