Impact
Improper neutralization of input during web page generation (CWE‑79) allows stored cross‑site scripting in the Imran Emu TC Testimonials WordPress plugin. A malicious actor can post a testimonial containing a script that is saved and subsequently executed in the browsers of any visitor to the site, potentially leaking confidential data, hijacking sessions or defacing pages.
Affected Systems
The flaw exists in TC Testimonials plugin versions from the earliest release through 1.1.1 on WordPress installations, meaning any site using one of those versions is vulnerable.
Risk and Exploitability
The CVSS score of 10.0 indicates maximum severity, while the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability can be exploited simply by submitting a crafted testimonial that includes malicious markup; if the site allows anonymous or public submissions, even non‑privileged users can trigger the stored XSS. Once the payload is rendered, it runs with the privileges of the visiting user and can lead to information disclosure, credential theft or defacement.
OpenCVE Enrichment
EUVD