CVE-2025-8666: Testimonial Carousel For Elementor <= 11.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions less than, or equal to, 11.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8666?
CVE-2025-8666 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-8666?
To mitigate CVE-2025-8666, upgrade the Testimonial Carousel For Elementor plugin to version 11.6.3 or later, where the vulnerabilities are patched.
What impact does CVE-2025-8666 have on my website?
CVE-2025-8666 could allow authenticated attackers to execute malicious scripts in the context of your users' browsers, risking data theft or site integrity.
Are all versions of the Testimonial Carousel For Elementor affected by CVE-2025-8666?
Yes, any version up to and including 11.6.2 of the Testimonial Carousel For Elementor plugin is affected by CVE-2025-8666.
Who is at risk for CVE-2025-8666?
Anyone using the Testimonial Carousel For Elementor plugin version 11.6.2 or earlier is at risk for CVE-2025-8666.