CVE-2025-11268: Strong Testimonials <= 3.2.16 - Unauthenticated Arbitrary Shortcode Execution
The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a doshortcode call. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes if an administrator previews or publishes a crafted testimonial.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11268?
CVE-2025-11268 is classified as a high-severity vulnerability due to the potential for arbitrary shortcode execution.
How do I fix CVE-2025-11268?
To fix CVE-2025-11268, update the Strong Testimonials plugin to version 3.2.17 or later.
What versions of Strong Testimonials are affected by CVE-2025-11268?
CVE-2025-11268 affects all versions of the Strong Testimonials plugin up to and including version 3.2.16.
What type of attack can CVE-2025-11268 facilitate?
CVE-2025-11268 can facilitate attacks that execute arbitrary code through unvalidated and unsanitized user input.
Is CVE-2025-11268 considered a critical vulnerability?
While CVE-2025-11268 is high in severity, it may not be labeled critical as the impact is limited to certain functionalities.