Medium severity6.4NVD Advisory· Published May 10, 2026· Updated May 12, 2026
CVE-2022-50947
CVE-2022-50947
Description
WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field that execute in the browsers of users viewing the draft post, enabling cookie theft and session hijacking.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=2.2.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.