A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.
CVE ID: CVE-2024-38345
Vendor: Sola Plugins
Product: Sola Testimonials
EPSS Score: 0.07% (probability of being exploited)
EPSS Percentile: 18.4% (scored less or equal to compared to others)
EPSS Date: 2025-04-11 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false