Executive brief
Real Testimonials is a WordPress plugin used to display customer reviews and testimonials on websites. A security vulnerability in versions 3.1.15 and earlier allows an attacker with administrative privileges to inject malicious code into the site. If exploited, this could lead to full site takeover, data theft, or service disruption, though it requires high-level access to initiate.
Technical details
A PHP Object Injection vulnerability exists in the Real Testimonials (testimonial-free) plugin for WordPress due to the insecure deserialization of user-supplied input. An attacker with high privileges (Administrator) can exploit this to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or file system manipulation. The issue is fixed in version 3.1.16.
Affected products
- ShapedPlugin LLC Real Testimonials (testimonial-free) <= 3.1.15
Timeline
- 2026-06-30: other: Vulnerability reported by researcher Ananda Dhakal
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Patch confirmed available in version 3.1.16