Stored XSS in Strong Testimonials WordPress Plugin
The Strong Testimonials WordPress plugin (up to version 3.3.11) is vulnerable to stored Cross-Site Scripting (XSS) via the 'platform_user_photo' custom field, allowing unauthenticated attackers to execute malicious scripts in victims' browsers.
CVE search metadata
CVE search record: CVE-2026-96650. Severity: high. CVSS: 7.2. KEV: no. Product: Strong Testimonials (<= 3.3.11). Brief: Stored XSS in Strong Testimonials WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96650/
The Strong Testimonials plugin for WordPress contains a vulnerability (CVE-2026-96650) affecting all versions up to and including 3.3.11. The vulnerability arises from insufficient input sanitization and output escaping within the 'platform_user_photo' custom field. An unauthenticated attacker can exploit this by submitting a testimonial containing malicious JavaScript through a public-facing submission form.
For the attack to succeed, the site administrator must have specifically configured the testimonial submission form to include custom text fields named 'platform' and 'platform_user_photo'. Because the plugin does not restrict these internal metadata keys, the injected script is stored in the site database. The script subsequently executes in the browser of any user, including administrators, who views the page where the testimonial is displayed. This impact is significant for organizations relying on user-generated content, as it facilitates session hijacking, credential theft, or unauthorized actions performed on behalf of authenticated administrative users.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the WordPress site. This can lead to the compromise of administrative sessions, modification of site content, and potential redirection of site visitors to malicious domains. The vulnerability affects any WordPress instance utilizing the Strong Testimonials plugin with the aforementioned specific custom form fields enabled.
Recommendation
- Immediately upgrade the Strong Testimonials plugin to the latest available version beyond 3.3.11.
- Audit all public-facing testimonial forms to determine if custom fields named 'platform' or 'platform_user_photo' have been manually configured.
- If immediate patching is not possible, temporarily remove the 'platform' and 'platform_user_photo' custom fields from testimonial submission forms until the plugin is updated.
- Implement or update Content Security Policy (CSP) headers to restrict the execution of inline scripts and unauthorized third-party domains to mitigate the impact of stored XSS.
Immediate actions
Upgrade Strong Testimonials plugin
Mitigations
Disable custom fields 'platform' and 'platform_user_photo' in form configurations
CVE-2026-96650