Junglewise Threat Intelligence

CVE-2026-3239: WPChill Strong Testimonials Stored XSS in testimonial_view shortcode

CVE-2026-3239 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Vendors: WPChill.

Executive brief

Strong Testimonials is a popular WordPress plugin used to display customer reviews and feedback on websites. A security flaw allows users with basic contributor-level access to embed malicious scripts into testimonial pages. When other visitors or administrators view these pages, the scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'testimonial_view' shortcode. This vulnerability affects all versions up to and including 3.2.21. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into pages. Because the scripts are stored on the server, they execute in the context of any user's browser who views the compromised page. A patch appears to have been addressed in changeset 3470120.

Affected products

  • WPChill Strong Testimonials <= 3.2.21

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References