PT-2020-16483 · WordPress · Testimonial Rotator Wordpress Plugin
Published
2020-10-16
·
Updated
2020-11-19
·
CVE-2020-26672
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Testimonial Rotator Wordpress Plugin version 3.0.2
Description
The issue concerns a Cross Site Scripting (XSS) problem. Specifically, it involves the /wp-admin/post.php endpoint. If a user intercepts a request and inserts a payload in the
cite parameter, the payload will be stored in the database.Recommendations
For Testimonial Rotator Wordpress Plugin version 3.0.2, consider restricting access to the /wp-admin/post.php endpoint until a fix is available. As a temporary workaround, avoid using the
cite parameter in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Testimonial Rotator Wordpress Plugin