Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability in Strong Testimonials
The changelog entries for the latest version of the WordPress plugin Strong Testimonials indicated that a security vulnerability had been fixed:
…
The changelog entries for the latest version of the WordPress plugin Strong Testimonials indicated that a security vulnerability had been fixed:
…
We often find that vulnerabilities haven’t been fully resolved when the WPScan Vulnerability Database claims they have. That is the case with the plugin Strong Testimonials, where they previously listed that some of the plugin’s AJAX accessible functionality was not properly secured.
…