PT-2024-38318 · WordPress · Testimonials Widget

Francesco Carlucci

·

Published

2024-08-20

·

Updated

2024-09-27

·

CVE-2024-7390

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Testimonial Widget plugin for WordPress versions up to, and including, 3.0
Description The issue is related to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function. This allows unauthenticated attackers to change the order of testimonials.
Recommendations For versions up to, and including, 3.0, consider disabling the fnSaveTestimonailOrder function until a patch is available to prevent unauthorized modification of data.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7390

Affected Products

Testimonials Widget