What the vulnerability does
01Description
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The Testimonial WordPress plugin version 1.6.1 and earlier contains a stored cross-site scripting (XSS) vulnerability. An authenticated admin user with high privileges can inject malicious JavaScript into testimonial content. When other users view the affected page, the injected script executes in their browser, potentially compromising their session or stealing sensitive data.
What an attacker can do
Inject malicious JavaScript that executes when other users view testimonials.
Potential impact on your site
A compromised admin account can inject persistent malicious code affecting all site visitors.
Conditions required to exploit
Admin-level access to the WordPress site and user interaction (victim must view the affected page).
Key dates
External resources
Related vulnerabilities