Impact
The Testimonial Carousel for Elementor plugin contains a stored cross‑site scripting flaw that permits authenticated users with contributor or higher privileges to inject arbitrary JavaScript into widget parameters. The flaw arises from insufficient sanitization and output escaping, causing the plugin to persist malicious scripts in the database and render them when a page containing the widget is accessed. An attacker could use the injected script to deface the site, steal user session cookies, or execute other malicious payloads in the browser context of legitimate visitors. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites that have the Testimonial Carousel for Elementor plugin installed at version 11.6.2 or earlier are affected. The plugin is distributed by uapp and the vulnerability applies to all widgets that accept input fields shown in the code references. Site administrators should verify that no older versions are active and note that only users with contributor-level or administrative roles can exploit the issue.
Risk and Exploitability
The CVSS score of 6.4 classifies this vulnerability as medium, and the EPSS score of less than 1% indicates a low expected exploitation rate. The flaw is not listed in the CISA KEV catalog, further suggesting limited known activity. Exploitation requires authenticated contributor access, so attackers must first compromise a user account or obtain credentials. Once the account is available, the attacker can submit malicious widget content that is stored and executed for any subsequent visitor to the affected page.
OpenCVE Enrichment