Impact
A Cross‑Site Request Forgery flaw in the Web Testimonials plugin allows an attacker to forge an authorized request that inserts arbitrary JavaScript into testimonial content. The injected code is stored and will run in the browsers of any user who views the impacted testimonial. This Stored XSS can steal session cookies, deface pages, or redirect users to malicious sites.
Affected Systems
The vulnerability affects the WordPress Web Testimonials plugin from unknown initial releases through version 1.2. Any WordPress site that has the plugin installed at or below this version is impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity exploit. The EPSS score is below 1 %, so active exploitation is currently rare. The vulnerability is not listed in CISA KEV. Attackers can likely exploit it by crafting a CSRF payload either via a link or form, requiring the target to be authenticated admin or a logged‑in user. No specific network requirement is stated, but the exploit requires the victim to have the plugin installed and active.
OpenCVE Enrichment
EUVD