SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8549

Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.

MEDIUM 6.1EPSS 1.88%

Does this matter?

Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.

Description

Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.88% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
wpchill/strong testimonials
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.