CVE-2024-7390

Publication date

2024-08-21 05:30:20

Family

Wordfence

State

PUBLISHED

Description

The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to change the order of testimonials.