CVE-2024-38345
Published
CVSS v3
8.1
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.
<p>The easiest to use Testimonial plugin! Showcase your testimonials in a beautiful and modern way with Super Testimonials.</p>
<h4>Lite Features</h4>
<ul>
<li>Fully comprehensive testimonial manager</li>
<li>Add testimonials to your site in seconds</li>
<li>Responsive</li>
<li>Show all testimonials via a shortcode</li>
<li>Show a single testimonial via a shortcode</li>
<li>Show a random testimonial via a shortcode</li>
<li>Five layouts to choose from: single coloumn, two columns, three columns, four columns and a blank layout</li>
<li>Two beautiful, modern themes to choose from</li>
<li>Add custom CSS to create your own testimonial styles and themes</li>
<li>Testimonials are created using custom post types</li>
<li>Show testimonials within a widget using shortcodes</li>
<li>Display testimonials using an easy testimonial widget</li>
<li>Gravatar images or custom images can be used</li>
<li>Show/hide the testimonial title</li>
<li>Show/hide the testimonial body</li>
<li>Set the except length of the testimonial</li>
<li>Set the read more link</li>
<li>Show/hide the testimonial name</li>
<li>Show/hide the testimonial website and link</li>
<li>Toggle ‘nofollow’ website links</li>
<li>All testimonial links are nofollow as per Google Webmaster Guidelines</li>
<li>Show/hide the testimonial image</li>
<li>Customizable filters</li>
</ul>
<h4>Premium Features</h4>
<ul>
<li>Two additional themes</li>
<li>New themes added every week</li>
<li>Responsive</li>
<li>Display testimonials in a responsive slider. </li>
<li>Allow users to submit a testimonial through an easy to use and customizable form</li>
<li>Get notified via email when a new testimonial has been submitted</li>
<li>Enable CAPTCHA in your testimonial submission form</li>
<li>Categorize your testimonials</li>
<li>Easy to use slider testimonial widget</li>
<li>Allow users to submit reviews (star ratings included in testimonial)</li>
<li>Export testimonials into a CSV file</li>
<li>Get notified via Slack when a new testimonial has been submitted</li>
<li>Priority <a href="http://codecabin.io/store/support/" rel="nofollow ugc">support</a> </li>
<li>Get the <a href="https://codecabin.io/store/super-testimonials-pro/?utm_source=wordpress&utm_medium=click&utm_campaign=readme" rel="nofollow ugc">Super Testimonials Premium Version</a> now</li>
</ul>
<h4>Coming Soon</h4>
<ul>
<li>Themes: Testimonial themes will be created and added every week</li>
<li>Allow multiple testimonials to be selected within one shortcode</li>
<li>Triggers (Request users to submit a testimonial after a specified action)</li>
</ul>
<h4>Shortcodes</h4>
<p>Show all Testimonials<br />
[super_t_all_testimonials]</p>
<p>Show all Testimonials of a certain category<br />
[super_t_all_testimonials cat_id=6]</p>
<p>Show a random testimonial from a certain category<br />
[super_t_all_testimonials cat_id=6 random=yes]</p>
<p>Show all Testimonials with a specific theme<br />
[super_t_all_testimonials theme=theme-1]</p>
<pre><code>[super_t_all_testimonials theme=theme-2]
[super_t_all_testimonials theme=theme-3]
[super_t_all_testimonials theme=theme-4]
[super_t_all_testimonials theme=theme-5]
</code></pre>
<p>Show all Testimonials with a specific layout<br />
[super_t_all_testimonials layout=layout-1]</p>
<pre><code>[super_t_all_testimonials layout=layout-2]
[super_t_all_testimonials layout=layout-3]
[super_t_all_testimonials layout=layout-4]
</code></pre>
<p>Show a random testimonial<br />
[super_t_all_testimonials random=yes]</p>
<p>Show a single testimonial<br />
[super_testimonial id=1]</p>
<p>Show a single testimonial with a specific theme<br />
[super_testimonial theme=theme-1 id=1]</p>
<p>Show a single testimonial with a specific layout<br />
[super_testimonial layout=layout-1]</p>
<p>Show all Testimonials in a responsive slider (Pro)<br />
[super_testimonial_slider]</p>
<p>Show all Testimonials of a certain category in a responsive slider (Pro)<br />
[super_testimonial_slider cat_id=1]</p>
<p>Show all Testimonials in a responsive slider (Pro)<br />
[super_testimonial_slider theme=theme-1]</p>
<p>Testimonial submit form (Pro)<br />
[super_testimonial_submit_form]</p>
<p>Show all Testimonials with pagination enabled<br />
[super_t_all_testimonials per_page=2]</p>
<p>Display total count of all testimonials<br />
[super_testimonials_count type=’any’]</p>
<p>Display total count of all approved testimonials<br />
[super_testimonials_count type=’approved’]</p>
<p>Display total count of all pending testimonials<br />
[super_testimonials_count type=’pending’]</p>
<h4>Translations</h4>
<p>Get a free copy of the Super Testimonials Premium version in exchange for translating our plugin!</p>
<ul>
<li>English (Default)</li>
<li>Swedish (Jorgen Sjoholm)</li>
<li>Brazilian Portuguese (Marcio Marodin)</li>
<li>Spanish (Esteban Truelsegaard)</li>
<li>Dutch (Albert van der Ploeg)</li>
<li>French (Frederic Grolleau)</li>
</ul>
<h4>How to effectively use testimonials</h4>
<p>One of the most important tasks of your website is to educate potential customers of your product and/or service. Using effective testimonials is an important step in this process and highlighting the right testimonials is of the utmost importance.</p>
<p>Did you know that 90% of people trust testimonials from people they know, and that 70% of people trust testimonials of strangers posted online? (Neilsen, 2009)</p>
<ul>
<li>Testimonials build trust. Nothing is more trustworthy than seeing a real person talking highly of your product or service</li>
<li>Testimonials can answer important questions</li>
<li>Testimonials overcome buyer skepticism by showing how your product has helped others</li>
<li>A testimonial can substantiate claims that you have made on your website</li>
<li>By including a first name, last name and company name in the testimonial, you are showing that your testimonials are coming from real people</li>
</ul>