Cross-site Scripting Flaw in Easy Testimonials Plugin for WordPress
CVE-2017-12131

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 August 2017

Summary

The Easy Testimonials plugin version 3.0.4 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. This issue manifests within the display.options.php file, impacting settings related to Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens. Attackers can exploit this flaw to inject malicious scripts, potentially compromising the integrity of the affected website and endangering users' data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.