The Testimonials Project maintains a narrowly scoped testimonials collection and display component, presenting a modest attack surface centered on web-page rendering and user input handling. Its vulnerability profile reflects the typical exposure pattern for such display-oriented utilities, with the durable signal concentrated on cross-site scripting weaknesses that arise from insufficient input sanitization during content generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Testimonials Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33191MEDIUM Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testimonials plugin <= 3.0.1 at WordPress. | Jul 22, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Testimonials Project.
Media articles that mention a CVE ID that affects a product developed by Testimonials Project — matched by CVE ID, not by vendor name.