PT-2020-16483 · WordPress · Testimonial Rotator Wordpress Plugin

Published

2020-10-16

·

Updated

2020-11-19

·

CVE-2020-26672

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Testimonial Rotator Wordpress Plugin version 3.0.2
Description The issue concerns a Cross Site Scripting (XSS) problem. Specifically, it involves the /wp-admin/post.php endpoint. If a user intercepts a request and inserts a payload in the cite parameter, the payload will be stored in the database.
Recommendations For Testimonial Rotator Wordpress Plugin version 3.0.2, consider restricting access to the /wp-admin/post.php endpoint until a fix is available. As a temporary workaround, avoid using the cite parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26672

Affected Products

Testimonial Rotator Wordpress Plugin