Vulnerability CVE-2024-7390


Published: 2024-08-21

Description:
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to change the order of testimonials.

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/67eef869-a57f-40b5-b289-9353bf5b680a?source=cve
https://plugins.trac.wordpress.org/browser/wp-testimonial-widget/trunk/functions.php#L358

Copyright 2026, cxsecurity.com

 

Back to Top