CVE-2020-8549: XSS
Published Feb 3, 2020
·Updated
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
Affected Software
2 affected components
WPChill Strong Testimonials Wordpress<2.40.1
Machothemes Strong Testimonials Wordpress<2.40.1
Event History
Feb 3, 2020
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8549?
CVE-2020-8549 is classified as a high severity vulnerability due to its potential for exploitation through stored XSS attacks.
2
How do I fix CVE-2020-8549?
To fix CVE-2020-8549, upgrade the Strong Testimonials plugin to version 2.40.1 or later.
3
What type of attacks can be performed using CVE-2020-8549?
CVE-2020-8549 can be exploited to perform stored XSS attacks, allowing attackers to steal session tokens.
4
Which versions of Strong Testimonials are affected by CVE-2020-8549?
CVE-2020-8549 affects versions of the Strong Testimonials plugin prior to 2.40.1.
5
Is there a recommended mitigation for CVE-2020-8549?
The recommended mitigation for CVE-2020-8549 is to immediately update the plugin to the latest patched version.