What the vulnerability does
01Description
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16.
Explanation of Vulnerability in Simple Terms
Strong Testimonials through version 3.1.16 does not properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read data they should not have access to. The vulnerability requires an active WordPress account but no special interaction from the victim.
What an attacker can do
Read testimonial or plugin data that should be restricted to higher-privilege users.
Potential impact on your site
User data or testimonials may be exposed to unauthorized account holders on your site.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities