Loading product vulnerabilities…
Total
3
Critical
0
High
0
Medium
2
CISA KEV
0
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).