PT-2025-54173 · WordPress · Strong Testimonials

Raldea89

·

Published

2025-12-30

·

Updated

2025-12-30

·

CVE-2025-14426

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Strong Testimonials plugin for WordPress versions up to and including 3.2.18
Description The Strong Testimonials plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the edit rating() function. Authenticated attackers with Contributor-level access or higher can modify or delete rating meta on any testimonial post, even those created by other users. This is achieved by reusing a valid nonce obtained from their own testimonial edit screen.
Recommendations Update the Strong Testimonials plugin to a version later than 3.2.18.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14426

Affected Products

Strong Testimonials