CVE-2022-23912: AP Custom Testimonial < 1.4.8 - Reflected Cross-Site Scripting
Published Feb 28, 2022
·Updated
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
Affected Software
1 affected component
Accesspressthemes Ap Custom Testimonial Wordpress<1.4.7
Event History
Feb 28, 2022
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23912?
CVE-2022-23912 refers to a vulnerability in the Testimonial WordPress Plugin before version 1.4.7, which allows for Reflected cross-Site Scripting (XSS) attacks.
2
What software is affected by CVE-2022-23912?
The Accesspressthemes Ap Custom Testimonial WordPress plugin version up to 1.4.7 is affected by CVE-2022-23912.
3
How severe is CVE-2022-23912?
CVE-2022-23912 has a severity rating of 6.1 (Medium).
4
How can I fix CVE-2022-23912?
To fix CVE-2022-23912, update the Testimonial WordPress Plugin to version 1.4.7 or newer.
5
Where can I find more information about CVE-2022-23912?
You can find more information about CVE-2022-23912 in the plugin's change log and on the WPScan vulnerability report.