Uapp develops a modestly represented plugin product, Testimonial Carousel for Elementor, that extends the WordPress page-building ecosystem with structured content display functionality. The recurring vulnerability surface centers on web-tier input handling and access-control gaps, specifically cross-site scripting and missing authorization mechanisms that are characteristic of extensible platform plugins. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uapp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8666MEDIUM The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 due to i | Oct 25, 2025 | 6.4 | 22 | NO | NO |
CVE-2024-2253MEDIUM The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values the plugin's carousel widgets in all versions up to, and inc | May 30, 2024 | 6.4 | 20 | NO | NO |
CVE-2024-4698MEDIUM The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in | May 18, 2024 | 6.4 | 18 | NO | NO |
CVE-2024-4858MEDIUM The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_ca | May 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-35713MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UAPP GROUP Testimonial Carousel For Elementor allows Stored XSS.This is | Jun 8, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uapp.
Media articles that mention a CVE ID that affects a product developed by Uapp — matched by CVE ID, not by vendor name.