VulnerabilityModified
CVE-2022-23912
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
MEDIUM 6.1EPSS 0.87%
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- accesspressthemes/ap custom testimonial
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2664185Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/09512431-aa33-4514-8b20-1963c5d89f33Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2664185Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/09512431-aa33-4514-8b20-1963c5d89f33Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.