CVE-2025-68075
Deferred Deferred - Pending Action
Cross-Site Scripting (XSS) in BNE Testimonials <= 2.0.8

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack bne_testimonials to 2.0.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress BNE Testimonials Plugin, versions 2.0.8 and below, contains a Cross Site Scripting (XSS) vulnerability. This security flaw allows attackers to inject malicious scripts into websites using the plugin.

Exploitation requires user interaction, such as clicking a malicious link or visiting a specially crafted page.

Impact Analysis

This vulnerability can lead to attackers executing malicious scripts in the context of the affected website, potentially compromising user data, session tokens, or performing unauthorized actions.

The CVSS score of 6.5 indicates a moderate risk, meaning the impact can be significant but requires user interaction to exploit.

Users of the plugin are advised to update immediately or seek assistance to mitigate the risk.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update the BNE Testimonials WordPress plugin to a version higher than 2.0.8 as soon as an official patch becomes available.

If an official patch is not yet available, users are advised to seek assistance from their hosting provider or web developer to apply temporary mitigations or workarounds.

Compliance Impact

The provided information does not specify how the Cross Site Scripting (XSS) vulnerability in BNE Testimonials Plugin versions 2.0.8 and below impacts compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-68075. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart