First published: Mon Apr 04 2022(Updated: )
Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Web-settler Testimonial Slider | <=3.5.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36851 is an authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in the Web-Settler Testimonial Slider plugin for WordPress.
CVE-2021-36851 has a severity rating of 5.4, which is considered medium.
Versions up to and including 3.5.8.3 of the Web-Settler Testimonial Slider plugin for WordPress are affected by CVE-2021-36851.
To fix the CVE-2021-36851 vulnerability, you should update the Web-Settler Testimonial Slider plugin to a version beyond 3.5.8.3.
You can find more information about CVE-2021-36851 at the following references: [https://patchstack.com/database/vulnerability/testimonial-add/wordpress-testimonial-slider-plugin-3-5-8-3-cross-site-scripting-xss-vulnerability](https://patchstack.com/database/vulnerability/testimonial-add/wordpress-testimonial-slider-plugin-3-5-8-3-cross-site-scripting-xss-vulnerability) and [https://wordpress.org/plugins/testimonial-add/#developers](https://wordpress.org/plugins/testimonial-add/#developers).