Strong Testimonials
Vendor:
First CVE: Feb 3, 2020 · Active for 6 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Strong Testimonials over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2020
6 years ago
Most Recent CVE
Apr 8, 2026
109 days ago
CVE Severity & Scoring
Strong Testimonials12 CVEs
83%
17%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (58.3%)
Unknown0 (0.0%)
Required5 (41.7%)
Privileges Required
Low7 (58.3%)
High1 (8.3%)
None4 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3239MEDIUM The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 d | Apr 8, 2026 | 6.4 | 25 | NO | NO |
CVE-2024-47362HIGH Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16. | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-52123HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPChill Strong Testimonials.This issue affects Strong Testimonials: from n/a through 3.1.10. | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-24957MEDIUM Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects S | Feb 3, 2026 | 6.5 | 22 | NO | NO |
CVE-2020-8549MEDIUM Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens. | Feb 3, 2020 | 6.1 | 22 | NO | NO |
CVE-2025-7367MEDIUM The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insu | Jul 15, 2025 | 6.4 | 19 | NO | NO |
CVE-2025-14426MEDIUM The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up t | Dec 30, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-11268MEDIUM The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users | Nov 6, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-26975MEDIUM Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Te | Feb 25, 2025 | 5.3 | 17 | NO | NO |
CVE-2023-26013MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 versions. | Jun 16, 2023 | 5.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Strong Testimonials
Top CWEs
Versions
No cataloged versions.