What the vulnerability does
01Description
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI API key, disabling the feature.
Explanation of Vulnerability in Simple Terms
02Summary
The Testimonial Carousel For Elementor plugin for WordPress does not properly check user permissions before allowing certain actions. An unauthenticated attacker can make requests to the site that cause a denial of service by consuming server resources. Update to a version newer than 10.2.0.
What an attacker can do
03Attacker Capabilities
Make unauthenticated requests that degrade site performance or cause temporary unavailability.
Potential impact on your site
04Site Impact
Site may become slow or unresponsive during an attack; no data theft or modification.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 25, 2024
CVE published
April 8, 2026
Record updated