Stored Cross-Site Scripting Vulnerability in Strong Testimonials Plugin for WordPress
CVE-2026-92622
6.4MEDIUM
What is CVE-2026-92622?
The Strong Testimonials plugin for WordPress is exposed to a stored cross-site scripting vulnerability due to inadequate sanitization of input and insufficient output escaping via the 'lightbox_class' shortcode attribute. This vulnerability affects all versions up to and including 3.3.8. Attackers with contributor-level access or higher can exploit this issue to inject malicious web scripts into testimonials pages, which can execute when users access the compromised page. Exploitation occurs specifically when a testimonial view has a published testimonial with a featured image and the lightbox wrapper enabled, allowing the attack to be triggered during thumbnail rendering.
Affected Version(s)
Strong Testimonials 0 <= 3.3.8