Stored Cross-Site Scripting Vulnerability in WH Testimonials Plugin for WordPress
CVE-2023-1372
What is CVE-2023-1372?
The WH Testimonials plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. Attackers can exploit this weakness by injecting malicious scripts into various parameters, including wh_homepage, wh_text_short, and wh_text_full. Once a user accesses a compromised page, the injected scripts execute, potentially leading to unauthorized actions or data theft. This vulnerability affects all versions of the plugin up to and including 3.0.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WH Testimonials * <= 3.0.0
WH Testimonials 3.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved