CVE-2025-22269: WordPress Real Testimonials plugin <= 3.1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials allows Stored XSS. This issue affects Real Testimonials: from n/a through 3.1.6.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22269?
The severity of CVE-2025-22269 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-22269?
The recommended fix for CVE-2025-22269 is to upgrade the Real Testimonials plugin to version 3.1.7 or later.
What are the potential impacts of CVE-2025-22269?
If exploited, CVE-2025-22269 can allow attackers to execute malicious scripts in the context of user sessions.
Which versions of Real Testimonials are affected by CVE-2025-22269?
CVE-2025-22269 affects all versions of Real Testimonials from n/a up to and including 3.1.6.
Is CVE-2025-22269 specific to any platform?
Yes, CVE-2025-22269 specifically affects the ShapedPlugin LLC Real Testimonials and WordPress implementations of the plugin.