CVE-2023-6491: fallo de gravedad media en wpchill Strong Testimonials
Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modification
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.3epss 0.3%
probabilidad de explotación
0.3%top 81% de las CVE
explotación observada
noninguna fuente lo reporta
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
wpchill · Strong TestimonialsCVEs relacionadas — wpchill Strong Testimonials
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-92622MEDIUMStrong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode AttributeEPSS 0.3%CVE-2025-11268MEDIUMStrong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.3%CVE-2026-3239MEDIUMStrong Testimonials <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view ShortcodeEPSS 0.3%CVE-2026-96650HIGHStrong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom FieldEPSS 0.3%CVE-2025-7367MEDIUMStrong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom FieldsEPSS 0.2%CVE-2025-14426MEDIUMStrong Testimonials <= 3.2.18 - Missing Authorization to Authenticated (Contributor+) Rating Meta UpdateEPSS 0.2%