CVE-2026-96650
Received Received - Intake

Stored XSS in Strong Testimonials WordPress Plugin

Vulnerability report for CVE-2026-96650, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
strong_testimonials strong_testimonials to 3.3.11 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Strong Testimonials WordPress plugin has a stored cross-site scripting (XSS) vulnerability in versions up to 3.3.11. It occurs because the plugin fails to properly sanitize input for the 'platform_user_photo' custom field and escape output. Attackers can inject malicious scripts into testimonial pages that execute when users view them. This requires an administrator to have added specific custom text fields named 'platform' and 'platform_user_photo' to a public testimonial form.

The vulnerability exists due to insufficient input sanitization and output escaping in the plugin's handling of these custom fields.

Detection Guidance

Check WordPress installations for the Strong Testimonials plugin versions up to 3.3.11. Inspect testimonial submission forms for custom fields named 'platform' and 'platform_user_photo'. Review stored testimonials for suspicious scripts in the 'platform_user_photo' field.

Impact Analysis
  • Attackers can steal user session cookies or sensitive data by injecting malicious scripts into testimonial pages.
  • Visitors to infected pages may have their browsers compromised, leading to further malware infections or phishing attacks.
  • The plugin's functionality could be disrupted or defaced by unauthorized script execution.
  • Unauthenticated attackers can exploit this without needing user credentials.
Compliance Impact

This vulnerability could lead to unauthorized access to user data, potentially violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. If exploited, it may result in data breaches that require regulatory notifications and impact compliance status.

Mitigation Strategies

Update the Strong Testimonials plugin to the latest version beyond 3.3.11. Remove any custom fields named 'platform' or 'platform_user_photo' from public testimonial forms. Sanitize and escape all user inputs in testimonial submissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96650. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart