Cross-site Scripting Flaw in Easy Testimonials Plugin for WordPress
CVE-2017-12131
6.1MEDIUM
Summary
The Easy Testimonials plugin version 3.0.4 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. This issue manifests within the display.options.php file, impacting settings related to Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens. Attackers can exploit this flaw to inject malicious scripts, potentially compromising the integrity of the affected website and endangering users' data.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability Reserved
Vulnerability published