Description
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted testimonial view has at least one published testimonial with a featured image and the lightbox wrapper enabled, as the vulnerable code path is only reached when a thumbnail is rendered.
Published: 2026-09-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw triggered by the 'lightbox_class' shortcode attribute in the Strong Testimonials WordPress plugin. Because the attribute value is not properly sanitized or escaped, an attacker who can edit or create testimonial shortcodes can inject arbitrary JavaScript that will run in the browsers of any user who views the affected testimonial page. This allows an authenticated contributor‑level or higher user to execute scripts with the privileges of the visiting user, potentially facilitating credential theft, session hijacking, defacement, or the delivery of malware.

Affected Systems

The issue affects the WordPress plugin Strong Testimonials from any vendor of WPChill up to version 3.3.8. All installations of these versions that deploy the lightbox wrapper with a featured image are vulnerable. Versions greater than 3.3.8 are not affected.

Risk and Exploitability

The flaw has a CVSS score of 6.4, indicating a moderate severity. The EPSS score is below 1%, implying a very low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in large‑scale attacks. Exploitation requires an authenticated user with contributor or higher access and a testimonial view that contains a featured image with the lightbox enabled. The likely attack vector is via the WordPress admin interface where the attacker crafts a malicious shortcode to be stored in the database and then viewed by other users.

Generated by OpenCVE AI on September 19, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Strong Testimonials to version 3.3.9 or later, which removes the vulnerable code path.
  • If an immediate upgrade is not possible, disable the lightbox wrapper on all testimonial views or revoke contributor‑level editing rights to prevent insertion of malicious attributes.
  • After updating, audit existing testimonial shortcodes for any injected 'lightbox_class' values and remove or escape any suspicious content.

Generated by OpenCVE AI on September 19, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpchill
Wpchill strong Testimonials
Vendors & Products Wordpress
Wordpress wordpress
Wpchill
Wpchill strong Testimonials

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted testimonial view has at least one published testimonial with a featured image and the lightbox wrapper enabled, as the vulnerable code path is only reached when a thumbnail is rendered.
Title Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpchill Strong Testimonials
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T19:35:57.073Z

Reserved: 2026-09-16T14:58:54.869Z

Link: CVE-2026-92622

cve-icon Vulnrichment

Updated: 2026-09-18T19:35:53.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:17:02.377

Modified: 2026-09-18T20:17:29.927

Link: CVE-2026-92622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')