Stars Testimonials Cross-site Scripting Vulnerability

MEDIUM (6.5) No Patch

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 7%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Stars Testimonials is a WordPress plugin that allows users to add interactive testimonials with sliders and masonry grids. The vulnerability discovered in version 3.3.4 of the plugin allows an attacker to inject malicious JavaScript code, potentially leading to cross-site scripting (XSS) attacks.

Am I affected?

You're affected if you use Stars Testimonials: from n/a through <= 3.3.4.
To check if your installation is vulnerable, run wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/func.php with the PHP command line tool (e.g., on Linux/Mac: php -r 'require __FILE__; print_r($stars_testimonials_with_slider_and_masonry_grid);') or use a plugin like WPScan.

Affected Products

WordPress.org / Stars Testimonials with Slider and Masonry Grid

How to fix

No public patch link found in the advisory. Contact the vendor directly for remediation guidance.

References