CVE-2023-45754: WordPress Easy Testimonial Slider and Form Plugin <= 1.0.18 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form allows Stored XSS.This issue affects Easy Testimonial Slider and Form: from n/a through 1.0.18.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-45754?
CVE-2023-45754 is an authenticated (admin+) stored Cross-Site Scripting (XSS) vulnerability in the I Thirteen Web Solution Easy Testimonial Slider and Form plugin version 1.0.18 and earlier.
What is the severity of CVE-2023-45754?
The severity of CVE-2023-45754 is medium with a severity value of 4.8.
Which software versions are affected by CVE-2023-45754?
CVE-2023-45754 affects I Thirteen Web Solution Easy Testimonial Slider and Form plugin versions up to and including 1.0.18.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-45754?
The Common Weakness Enumeration (CWE) ID for CVE-2023-45754 is CWE-79.
How can I fix CVE-2023-45754?
To fix CVE-2023-45754, update the I Thirteen Web Solution Easy Testimonial Slider and Form plugin to a version later than 1.0.18.