PatchSiren cyber security CVE debrief
CVE-2026-3239 wpchill CVE debrief
The Strong Testimonials plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21. This is due to insufficient input sanitization and output escaping on user supplied attributes. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts in pages that will execute when a user accesses an injected page. This vulnerability has a medium severity level with a CVSS score of 6.4.
- Vendor
- wpchill
- Product
- Strong Testimonials
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-25
Who should care
Users of the Strong Testimonials plugin for WordPress, particularly those with contributor-level access and above, should be aware of this vulnerability and take necessary actions to protect their sites. Site administrators and security teams should prioritize updating the plugin and monitoring for suspicious activity.
Technical summary
The vulnerability exists in the Strong Testimonials plugin for WordPress, specifically in the testimonial_view shortcode. The plugin does not properly sanitize user input and escape output, allowing authenticated attackers to inject arbitrary web scripts. The CVSS score for this vulnerability is 6.4, indicating a medium severity level. This plugin vulnerability allows attackers with contributor-level access to inject scripts that execute on page access.
Defensive priority
Medium priority should be given to updating the Strong Testimonials plugin to a version that addresses this vulnerability and implementing additional security measures.
Recommended defensive actions
- Update the Strong Testimonials plugin to a version that addresses this vulnerability.
- Implement additional security measures, such as input validation and output encoding, to prevent similar vulnerabilities.
- Monitor your site for suspicious activity and ensure that all user input is properly sanitized and escaped.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-04-08T05:16:05.567Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Deferred. Evidence is limited to public CVE and NVD data. Defenders should verify vulnerable versions, update status, and exposed deployments with the vendor and other sources.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T05:16:05.567Z and has not been modified since then. The NVD entry is currently Deferred.