Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-09-11

CVE-2025-7826 - Testimonial Plugin

The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Testimonial

CVE-2025-7826

MEDIUM CVSS 6.5 2025-09-10
Threat Entry Updated 2024-11-21

CVE-2022-23911 - Testimonial Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

PLUGIN Testimonial

CVE-2022-23911

HIGH CVSS 7.2 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-23912 - Testimonial Plugin

The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting

PLUGIN Testimonial

CVE-2022-23912

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24598 - Testimonial Plugin

The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Testimonial

CVE-2021-24598

MEDIUM CVSS 4.8 2021-11-17
Scroll to top