{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astrong_testimonials_projectstrong_testimonialswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:strong_testimonials_project:strong_testimonials:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96650"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Strong Testimonials (\u003c= 3.3.11)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Strong Testimonials plugin for WordPress contains a vulnerability (CVE-2026-96650) affecting all versions up to and including 3.3.11. The vulnerability arises from insufficient input sanitization and output escaping within the 'platform_user_photo' custom field. An unauthenticated attacker can exploit this by submitting a testimonial containing malicious JavaScript through a public-facing submission form.\u003c/p\u003e\n\u003cp\u003eFor the attack to succeed, the site administrator must have specifically configured the testimonial submission form to include custom text fields named 'platform' and 'platform_user_photo'. Because the plugin does not restrict these internal metadata keys, the injected script is stored in the site database. The script subsequently executes in the browser of any user, including administrators, who views the page where the testimonial is displayed. This impact is significant for organizations relying on user-generated content, as it facilitates session hijacking, credential theft, or unauthorized actions performed on behalf of authenticated administrative users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the WordPress site. This can lead to the compromise of administrative sessions, modification of site content, and potential redirection of site visitors to malicious domains. The vulnerability affects any WordPress instance utilizing the Strong Testimonials plugin with the aforementioned specific custom form fields enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade the Strong Testimonials plugin to the latest available version beyond 3.3.11.\u003c/li\u003e\n\u003cli\u003eAudit all public-facing testimonial forms to determine if custom fields named 'platform' or 'platform_user_photo' have been manually configured.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, temporarily remove the 'platform' and 'platform_user_photo' custom fields from testimonial submission forms until the plugin is updated.\u003c/li\u003e\n\u003cli\u003eImplement or update Content Security Policy (CSP) headers to restrict the execution of inline scripts and unauthorized third-party domains to mitigate the impact of stored XSS.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T06:54:39Z","date_published":"2026-10-03T06:54:39Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96650/","summary":"The Strong Testimonials WordPress plugin (up to version 3.3.11) is vulnerable to stored Cross-Site Scripting (XSS) via the 'platform_user_photo' custom field, allowing unauthenticated attackers to execute malicious scripts in victims' browsers.","title":"Stored XSS in Strong Testimonials WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96650/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:strong_testimonials_project:strong_testimonials:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}