Description
WordPress Plugin Testimonial WordPress-AP Custom Testimonial [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Testimonial WordPress-AP Custom Testimonial version 1.4.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.7 or latest
References
Related Vulnerabilities
WordPress Plugin PictoBrowser Cross-Site Request Forgery (0.3.1)
WordPress Plugin Request a Quote Cross-Site Scripting (2.3.4)
WordPress Plugin Zingiri Web Shop 'abspath' Parameter Remote File Include (2.4.6)
WordPress Plugin Music Store Unspecified Vulnerability (1.0.20)
WordPress Plugin FireCask Like & Share Button Cross-Site Scripting (1.1.5)