Back to Database
Status published
Medium
CVE-2020-8549
Stored XSS in the Strong Testimonials plugin before 2.40.1 for...
Vulnerability Description
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8549
Credits & Attribution
No credits recorded in the NVD database.
References
- https://wpvulndb.com/vulnerabilities/10056
- https://github.com/MachoThemes/strong-testimonials/blob/master/changelog.txt
- https://www.getastra.com/blog/911/plugin-exploit/stored-xss-vulnerability-found-in-strong-testimonials-plugin/
- https://www.jinsonvarghese.com/stored-xss-vulnerability-in-strong-testimonials-plugin/
- http://packetstormsecurity.com/files/156369/WordPress-Strong-Testimonials-2.40.1-Cross-Site-Scripting.html
More from wpchill
View All →CVE-2025-7367
Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields
Medium
6.4
CVE-2025-15466
Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management
Medium
5.4
CVE-2025-14865
Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium
6.4
CVE-2025-14632
Filr – Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload
Medium
4.4
CVE-2025-14455
Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management
Medium
5.4
Affected Vendor
wpchill
View all reports →Affected Software
strong testimonials
Vulnerable Versions:
0
Timeline
Official Publish:
February 3rd, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.