CVE-2022-3539: Testimonials (Free < 2.7, Pro < 1.0.8) - Admin+ Stored Cross-Site Scripting
The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3539?
CVE-2022-3539 is a vulnerability in the Testimonials WordPress plugin before version 2.7 and the super-testimonial-pro WordPress plugin before version 1.0.8.
What is the severity of CVE-2022-3539?
CVE-2022-3539 has a severity level of medium.
Which software versions are affected by CVE-2022-3539?
The Testimonials WordPress plugin before version 2.7 and the super-testimonial-pro WordPress plugin before version 1.0.8 are affected by CVE-2022-3539.
What is the impact of CVE-2022-3539?
CVE-2022-3539 allows high privilege users, such as admin, to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
How can I fix CVE-2022-3539?
To fix CVE-2022-3539, you should update the Testimonials WordPress plugin to version 2.7 or higher and the super-testimonial-pro WordPress plugin to version 1.0.8 or higher.