CVE-2026-97286: WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.
Affected Software
1 affected component
WordPress Strong Testimonials<=3.3.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Strong Testimonials pluginto a version that resolves this vulnerability.Fixed in 3.3.12
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as contributor XSS, so an attacker needs contributor-level access to the affected WordPress site.
2
Does exploitation require a victim to take an action?
Yes. The CVSS vector includes UI:R, indicating user interaction is required for exploitation.
3
Can this be exploited remotely?
Yes. The CVSS vector includes AV:N, meaning the vulnerable site can be targeted over the network, provided the attacker has the required contributor-level privileges.