CVE-2024-4858: Uapp Testimonial Carousel For Elementor

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI API key, disabling the feature.

Affected products

  • Uapp Testimonial Carousel For Elementor: before 10.2.1 (fixed in 10.2.1)

Published 2024-05-25. Last modified 2026-06-17.