CVE-2023-5613: Super Testimonials <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5613?
CVE-2023-5613 is a vulnerability in the Super Testimonials plugin for WordPress that allows for stored cross-site scripting.
How does CVE-2023-5613 affect the Super Testimonials plugin for WordPress?
CVE-2023-5613 affects all versions up to and including 2.9 of the Super Testimonials plugin for WordPress.
What is the severity of CVE-2023-5613?
The severity of CVE-2023-5613 is medium with a CVSS score of 6.4.
How can I fix CVE-2023-5613?
To fix CVE-2023-5613, users should update to a version of the Super Testimonials plugin for WordPress that includes a fix for the vulnerability.
Where can I find more information about CVE-2023-5613?
More information about CVE-2023-5613 can be found at the following references: [Reference 1](https://plugins.trac.wordpress.org/browser/super-testimonial/tags/2.8/tp-testimonials.php#L214), [Reference 2](https://plugins.trac.wordpress.org/changeset/2979378/super-testimonial#file9), [Reference 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/52659f1c-642e-4c88-b3d0-d5c5a206b11c?source=cve).