Impact
The BNE Testimonials plugin, when running a version earlier than 2.0.8.2, fails to escape a shortcode attribute that is used in a JavaScript context before it is inserted into an inline script. This defect allows a user who has the contributor role or higher to inject arbitrary JavaScript into the slider shortcode. When a visitor loads a page that includes the malicious content, the script executes in the visitor’s browser, potentially allowing session hijacking, credential theft, defacement or the delivery of additional malware. The weakness is an example of Input Validation failure and is defined by CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
WordPress sites that have installed the BNE Testimonials plugin with a version older than 2.0.8.2. Any user with the contributor role or higher on such a site has the ability to craft the malicious shortcode, and the vulnerability affects all visitors who view the page containing the injected code.
Risk and Exploitability
The exploit requires an authenticated attacker who can create or edit content as a contributor. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the publicly observed exploitation frequency is undetermined, but the impact on the client side is significant. Sites that restrict contributor access or employ strict role controls reduce the attack surface. Without mitigation, any outlet presenting the slider shortcode is at risk of client‑side compromise.
OpenCVE Enrichment