The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys.
cve CVE-2026-96650 2 sources, 2 claims · Watch
NVD writes:
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata… the claim
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata… the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | wpchill/strong_testimonialsNVD says “wpchill · Strong Testimonials” |
| made_by | wpchillNVD says “wpchill” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | GitHub advisories | 7.2receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96650",
"cvss": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys.",
"ghsa_id": "GHSA-3f97-cv73-464c",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3f97-cv73-464c",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3f97-cv73-464c"
},
{
"type": "CVE",
"value": "CVE-2026-96650"
}
],
"nvd_published_at": "2026-10-03T06:16:48Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96650",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275",
"https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials",
"https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve",
"https://github.com/advisories/GHSA-3f97-cv73-464c"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...",
"type": "unreviewed",
"updated_at": "2026-10-03T06:31:25Z",
"url": "https://api.github.com/advisories/GHSA-3f97-cv73-464c",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cvss cvss | NVD | 7.2receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Strong Testimonials",
"vendor": "wpchill",
"versions": [
{
"lessThanOrEqual": "3.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "security@wordfence.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys."
}
],
"id": "CVE-2026-96650",
"lastModified": "2026-10-03T06:16:48.290",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7,
"source": "security@wordfence.com",
"type": "Primary"
}
]
},
"published": "2026-10-03T06:16:48.290",
"references": [
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials"
},
{
"source": "security@wordfence.com",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve"
}
],
"sourceIdentifier": "security@wordfence.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security@wordfence.com",
"type": "Primary"
}
]
}
} | — |
| Cwe cwe | GitHub advisories | CWE-79receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96650",
"cvss": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys.",
"ghsa_id": "GHSA-3f97-cv73-464c",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3f97-cv73-464c",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3f97-cv73-464c"
},
{
"type": "CVE",
"value": "CVE-2026-96650"
}
],
"nvd_published_at": "2026-10-03T06:16:48Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96650",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275",
"https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials",
"https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve",
"https://github.com/advisories/GHSA-3f97-cv73-464c"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...",
"type": "unreviewed",
"updated_at": "2026-10-03T06:31:25Z",
"url": "https://api.github.com/advisories/GHSA-3f97-cv73-464c",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Product product | NVD | Strong Testimonialsreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Strong Testimonials",
"vendor": "wpchill",
"versions": [
{
"lessThanOrEqual": "3.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "security@wordfence.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys."
}
],
"id": "CVE-2026-96650",
"lastModified": "2026-10-03T06:16:48.290",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7,
"source": "security@wordfence.com",
"type": "Primary"
}
]
},
"published": "2026-10-03T06:16:48.290",
"references": [
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials"
},
{
"source": "security@wordfence.com",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve"
}
],
"sourceIdentifier": "security@wordfence.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security@wordfence.com",
"type": "Primary"
}
]
}
} | — |
| Severity severity | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96650",
"cvss": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.2,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-79",
"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
}
],
"description": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys.",
"ghsa_id": "GHSA-3f97-cv73-464c",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3f97-cv73-464c",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3f97-cv73-464c"
},
{
"type": "CVE",
"value": "CVE-2026-96650"
}
],
"nvd_published_at": "2026-10-03T06:16:48Z",
"published_at": "2026-10-03T06:31:13Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96650",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242",
"https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275",
"https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials",
"https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve",
"https://github.com/advisories/GHSA-3f97-cv73-464c"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...",
"type": "unreviewed",
"updated_at": "2026-10-03T06:31:25Z",
"url": "https://api.github.com/advisories/GHSA-3f97-cv73-464c",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Strong Testimonials",
"vendor": "wpchill",
"versions": [
{
"lessThanOrEqual": "3.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "security@wordfence.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys."
}
],
"id": "CVE-2026-96650",
"lastModified": "2026-10-03T06:16:48.290",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7,
"source": "security@wordfence.com",
"type": "Primary"
}
]
},
"published": "2026-10-03T06:16:48.290",
"references": [
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials"
},
{
"source": "security@wordfence.com",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve"
}
],
"sourceIdentifier": "security@wordfence.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security@wordfence.com",
"type": "Primary"
}
]
}
} | — |
| Vendor vendor | NVD | wpchillreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Strong Testimonials",
"vendor": "wpchill",
"versions": [
{
"lessThanOrEqual": "3.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "security@wordfence.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that an administrator has added custom text fields named 'platform' and 'platform_user_photo' to a public testimonial submission form, as the plugin does not reserve those internal metadata keys."
}
],
"id": "CVE-2026-96650",
"lastModified": "2026-10-03T06:16:48.290",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7,
"source": "security@wordfence.com",
"type": "Primary"
}
]
},
"published": "2026-10-03T06:16:48.290",
"references": [
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L260"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/class-strong-testimonials-form.php#L32"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L242"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/browser/strong-testimonials/tags/3.3.10/includes/functions-image.php#L275"
},
{
"source": "security@wordfence.com",
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3711376%40strong-testimonials&new=3711376%40strong-testimonials"
},
{
"source": "security@wordfence.com",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/73c8267c-8c03-4ee6-9d3e-e383188b82ad?source=cve"
}
],
"sourceIdentifier": "security@wordfence.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-79"
}
],
"source": "security@wordfence.com",
"type": "Primary"
}
]
}
} | — |