CVE-2022-4717: Strong Testimonials < 3.0.3 - Contributor+ Stored XSS via Shortcode
The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Strong Testimonials WordPress plugin?
The vulnerability ID for the Strong Testimonials WordPress plugin is CVE-2022-4717.
What is the severity of CVE-2022-4717?
CVE-2022-4717 has a severity value of 5.4, which is considered medium.
What does the Strong Testimonials WordPress plugin vulnerability allow attackers to do?
The vulnerability in the Strong Testimonials WordPress plugin allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Which version of the Strong Testimonials WordPress plugin is affected by CVE-2022-4717?
The Strong Testimonials WordPress plugin version up to and excluding 3.0.3 is affected by CVE-2022-4717.
Is there a fix available for CVE-2022-4717?
Yes, the fix for CVE-2022-4717 is to update the Strong Testimonials WordPress plugin to version 3.0.3 or later.