CVE-2025-67912: WordPress Stars Testimonials plugin <= 3.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gal Dubinski Stars Testimonials allows Stored XSS.This issue affects Stars Testimonials: from n/a through 3.3.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Stars Testimonials stars-testimonials-with-slider-and-masonry-grid allows Stored XSS.This issue affects Stars Testimonials: from n/a through <= 3.3.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67912?
CVE-2025-67912 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-67912?
To fix CVE-2025-67912, update the Stars Testimonials plugin to the latest version that addresses the stored XSS vulnerability.
What systems are affected by CVE-2025-67912?
CVE-2025-67912 affects the Stars Testimonials plugin for WordPress, specifically versions 3.3.4 and below.
What can attackers do with CVE-2025-67912?
Attackers can exploit CVE-2025-67912 to execute malicious scripts in the context of a user's browser through stored XSS.
Is CVE-2025-67912 easy to exploit?
Yes, CVE-2025-67912 can be easily exploited if the vulnerability is present, as it allows attackers to inject scripts that can affect users visiting the compromised site.