What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
Explanation of Vulnerability in Simple Terms
The Testimonials plugin for WordPress versions 2.6 and earlier contains a stored cross-site scripting (XSS) vulnerability. An authenticated user with high privileges can inject malicious JavaScript that executes in the browsers of other site visitors. The vulnerability requires user interaction to trigger and affects the plugin's data integrity and confidentiality.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view affected plugin content.
Potential impact on your site
Site visitors may be redirected, have sessions hijacked, or see malicious content injected by a privileged user.
Conditions required to exploit
Attacker must have high-level WordPress privileges (e.g., admin or editor role) and a victim must view the affected page.
Key dates
External resources
Related vulnerabilities