Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #6
WordPress plugin Testimonials by BestWebSoft hit by SQL injection flaw
Original: π¨ EUVD-2026-95705 π Score: 6.8/10 (CVSS v3.1) π¦ Product: Testimonials by BestWebSoft π’ Vendor: Unknown π Updated: 2026-1
A medium-severity vulnerability, tracked as EUVD-2026-95705 with a CVSS score of 6.8, has been disclosed in the Testimonials by BestWebSoft WordPress plugin up to version 1.0.8. The flaw stems from a parameter that is not sanitised or escaped before being used in a SQL query, allowing attackers to inject SQL. Site administrators running the plugin are being urged to review the advisory and update or remove the plugin.
Why now: Newly published vulnerability advisories about widely used WordPress plugins prompt security teams and site owners to check whether they are affected.
BestWebSoftTestimonials by BestWebSoftWordPressEUVD
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1606627