Starkdigital's vulnerability profile centers on WordPress plugins, including WP Testimonial Widget and Category Post List Widget, with disclosed issues concentrated in application-layer input-handling and authorization weaknesses such as cross-site scripting, SQL injection, cross-site request forgery, and missing authorization controls. These are characteristic flaws in community-contributed WordPress extensions where validation and access controls are inconsistently applied; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starkdigital over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43966HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: | Aug 26, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-47516MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through 2.0. | Nov 13, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-43967MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affect | Aug 26, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-7390MEDIUM The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all ve | Aug 21, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starkdigital.
Media articles that mention a CVE ID that affects a product developed by Starkdigital — matched by CVE ID, not by vendor name.