CVE-2021-36858: WordPress Testimonials plugin <= 2.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-36858?
CVE-2021-36858 is a Stored Cross-Site Scripting (XSS) vulnerability in the Themepoints Testimonials plugin <= 2.6 on WordPress that allows authenticated administrators to inject malicious scripts.
How severe is CVE-2021-36858?
CVE-2021-36858 has a severity rating of 4.8, which is considered medium.
Which software versions are affected by CVE-2021-36858?
CVE-2021-36858 affects versions up to and including 2.6 of the Themepoints Testimonials plugin on WordPress.
How can I mitigate CVE-2021-36858?
To mitigate CVE-2021-36858, it is recommended to update the Themepoints Testimonials plugin to a version greater than 2.6.
Where can I find more information about CVE-2021-36858?
You can find more information about CVE-2021-36858 on the Patchstack vulnerability database and the WordPress plugin page for Themepoints Testimonials.