Multiple Cross-Site Scripting Vulnerabilities in Easy Testimonials for WordPress
CVE-2020-14959

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 June 2020

Summary

The Easy Testimonials plugin for WordPress is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities due to improper input validation in several fields. Attackers can exploit these flaws by injecting arbitrary web scripts or HTML through parameters such as Client Name, Position, Web Address, and Review details. This allows unauthorized users to manipulate website content or execute malicious scripts in the context of users visiting the affected site.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.