Executive brief
The Fancy Testimonials plugin for WordPress, which allows site owners to display customer reviews, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into the website. These scripts will run automatically in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'author' attribute within the 'testimonial' shortcode. This vulnerability exists in all versions up to and including 1.0. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into pages. Because the payload is stored, the script executes in the context of any user's browser session when they visit the compromised page. The attack is reachable via the network and requires low privileges but no user interaction from the victim to trigger the execution.
Affected products
- dijitul Fancy Testimonials <= 1.0
Timeline
- 2026-06-18: disclosed: Initial disclosure by Wordfence and NVD publication.