CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content.
| Vendor | unknown |
| Product | bne testimonials |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown bne testimonials
Be the first to know when new unknown vulnerabilities affecting unknown bne testimonials are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / BNE Testimonials
0 < 2.0.8.2
References
Credits
testoun WPScan