Is "Easy Testimonials" safe?

WordPress Plugin security and safety information.

Rating: Good (current version safe) Recommendations

Easy Testimonials: Plugin Details


Type: Plugin
Author: Gold Plugins
URL: https://wordpress.org/plugins/easy-testimonials/
Latest Version: 3.7.1

 

Easy Testimonials: Security Information


Insecure versions: Up To 1.1
Known since: 2020-09-17 15:28:00
Description: The plugins only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed.


Insecure versions: Up To 1.1
Known since: 2020-05-14 11:15:41
Description: Multiple cross-site scripting vulnerabilities in Easy Testimonials 3.5.2 and lower allow an authenticated medium-privileged user (contributor+) to inject arbitrary javascript code which is executed when admin and other users access the All Testimonials page in the backend, as well as the testimonial is displayed in the frontend if the 'Allow HTML Tags in Testimonials' option is enabled (which it is by default).


Insecure versions: Up To 1.1
Known since: 2020-05-14 11:15:41
Description: Multiple cross-site scripting vulnerabilities in Easy Testimonials 3.5.2 and lower allow an authenticated medium-privileged user (contributor+) to inject arbitrary javascript code which is executed when admin and other users access the All Testimonials page in the backend, as well as the testimonial is displayed in the frontend if the 'Allow HTML Tags in Testimonials' option is enabled (which it is by default).


 

Easy Testimonials: Safety Recommendations


We have rated Easy Testimonials as Good (current version safe) which means that we have found vulnerabilities in older versions.

We recommend that you only use the latest version of Easy Testimonials.

Easy Testimonials: Staying Up-to-date


Make sure your installation of Easy Testimonials is safe with the following free Jetpack services for WordPress sites:
  • Updates & Management
    Turn on auto-updates for Easy Testimonials or manage in bulk.
  • Prevent Infiltrations
    Automatic protection against brute force attacks and secure sign on.

Choose Your Plan

Easy Testimonials: Keeping Safe


If you're running a business, ecommerce, news, or other critical website, Jetpack also provides additional indispensable services:
  • Automated Backups
    Full backup of your entire site with unlimited storage space.
  • Restores & Migrations
    Restore or migrate your site from a backup with one click.
  • Security Scanning
    Regular, automated scans of your site for malware, threats, and hacks.
  • Expert Support
    Fast, priority support for any WordPress security issue.

Choose Your Plan

About this information


This WordPress security information is part of our security library and is brought to you by Jetpack as part of our committment to a safer WordPress experience.

If you have any questions, please do not hesitate to contact us.