What the vulnerability does
01Description
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.
Explanation of Vulnerability in Simple Terms
The GS Testimonial Slider WordPress plugin through version 1.9.6 contains a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious JavaScript into testimonial content. When other users view the affected page, the injected script executes in their browser, potentially allowing session hijacking or credential theft.
What an attacker can do
Inject malicious JavaScript that runs when other users view testimonials.
Potential impact on your site
Authenticated users can inject scripts affecting other visitors; may lead to account compromise or data theft.
Conditions required to exploit
Attacker must have a low-privilege WordPress account and a victim must view the affected page.
Key dates
External resources
Related vulnerabilities