Multiple Cross-Site Scripting Vulnerabilities in Easy Testimonials for WordPress
CVE-2020-14959
5.4MEDIUM
Summary
The Easy Testimonials plugin for WordPress is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities due to improper input validation in several fields. Attackers can exploit these flaws by injecting arbitrary web scripts or HTML through parameters such as Client Name, Position, Web Address, and Review details. This allows unauthorized users to manipulate website content or execute malicious scripts in the context of users visiting the affected site.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved