Description
WordPress Plugin Testimonial WordPress-AP Custom Testimonial [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Testimonial WordPress-AP Custom Testimonial version 1.4.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.7 or latest
References
Related Vulnerabilities
WordPress Plugin Availability Calendar Cross-Site Scripting (1.2.1)
WordPress Plugin Cool Video Gallery Cross-Site Request Forgery (1.8)
WordPress Plugin WP User Groups Cross-Site Request Forgery (2.0.0)
WordPress Plugin wpCentral Security Bypass (1.4.7)
WordPress Plugin jRSS Widget 'url' Parameter Directory Traversal (1.1.1)