Input validation vulnerability in Super Testimonials 4.0.1

The Super Testimonials plugin for WordPress has a security issue where attackers can inject harmful code into pages through a parameter called ‘st_user_title’. This can happen in all versions up to 4.0.1 because the plugin does not properly clean up or protect against this type of attack. This means that someone who is not logged in to the website can cause their own code to run when other users access the page with the injected code.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.