The plugin does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed
As admin, create/edit a testimonial and put the following payload in the Testimonial User Name field: " style=animation-name:rotation onanimationstart=alert(/XSS/)//
Asif Nawaz Minhas
Asif Nawaz Minhas
Yes
2021-10-13 (about 8 months ago)
2021-10-13 (about 8 months ago)
2022-04-08 (about 3 months ago)