VYPR

Wp Testimonial Widget

Sign in to watch

by Starkdigital

CVEs (1)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-7390Med0.345.30.00Aug 21, 2024The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to change the order of testimonials.