Cross-site Scripting Flaw in Easy Testimonials Plugin for WordPress
CVE-2017-12131
6.1MEDIUM
What is CVE-2017-12131?
The Easy Testimonials plugin version 3.0.4 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. This issue manifests within the display.options.php file, impacting settings related to Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens. Attackers can exploit this flaw to inject malicious scripts, potentially compromising the integrity of the affected website and endangering users' data.