Stored Cross-Site Scripting Vulnerability in Tribute Testimonials Plugin for WordPress
CVE-2024-10886
6.4MEDIUM
What is CVE-2024-10886?
The Tribute Testimonials plugin for WordPress, specifically the tribute_testimonials_slider shortcode, is susceptible to stored cross-site scripting due to inadequate input sanitization and output escaping for user-supplied attributes. This vulnerability allows authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. These scripts can execute automatically when users access the affected pages, potentially compromising user data and site integrity.