First published: Tue Oct 24 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form allows Stored XSS.This issue affects Easy Testimonial Slider and Form: from n/a through 1.0.18.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.0.18 |
Update to 1.0.19 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45754 is an authenticated (admin+) stored Cross-Site Scripting (XSS) vulnerability in the I Thirteen Web Solution Easy Testimonial Slider and Form plugin version 1.0.18 and earlier.
The severity of CVE-2023-45754 is medium with a severity value of 4.8.
CVE-2023-45754 affects I Thirteen Web Solution Easy Testimonial Slider and Form plugin versions up to and including 1.0.18.
The Common Weakness Enumeration (CWE) ID for CVE-2023-45754 is CWE-79.
To fix CVE-2023-45754, update the I Thirteen Web Solution Easy Testimonial Slider and Form plugin to a version later than 1.0.18.