CVE-2024-7390
21.08.2024, 06:15
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to change the order of testimonials.Enginsight
Vendor | Product | Version |
---|---|---|
starkdigital | wp_testimonial_widget | 𝑥 ≤ 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration