CVE-2025-14127 | Testimonial Master Plugin up to 0.2.1 on WordPress $_SERVER['PHP_SELF'] cross site scripting
A vulnerability was found in Testimonial Master Plugin up to 0.2.1 on WordPress. It has been declared as problematic. This affects an unknown part. Executing a manipulation of the argument $_SERVER['PHP_SELF'] can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-14127. The attack may be launched remotely. There is no exploit available.