Impact
The vulnerability is a stored cross‑site scripting flaw triggered by the 'lightbox_class' shortcode attribute in the Strong Testimonials WordPress plugin. Because the attribute value is not properly sanitized or escaped, an attacker who can edit or create testimonial shortcodes can inject arbitrary JavaScript that will run in the browsers of any user who views the affected testimonial page. This allows an authenticated contributor‑level or higher user to execute scripts with the privileges of the visiting user, potentially facilitating credential theft, session hijacking, defacement, or the delivery of malware.
Affected Systems
The issue affects the WordPress plugin Strong Testimonials from any vendor of WPChill up to version 3.3.8. All installations of these versions that deploy the lightbox wrapper with a featured image are vulnerable. Versions greater than 3.3.8 are not affected.
Risk and Exploitability
The flaw has a CVSS score of 6.4, indicating a moderate severity. The EPSS score is below 1%, implying a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in large‑scale attacks. Exploitation requires an authenticated user with contributor or higher access and a testimonial view that contains a featured image with the lightbox enabled. The likely attack vector is via the WordPress admin interface where the attacker crafts a malicious shortcode to be stored in the database and then viewed by other users.
OpenCVE Enrichment