vendor:
Strong Testimonials
by:
Jinson Varghese Behanan
6.1
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Strong Testimonials
Affected Version From: 2.40.0
Affected Version To: 2.40.0
Patch Exists: YES
Related CWE: CVE-2020-8549
CPE: a:strong_testimonials:strong_testimonials:2.40.0
Platforms Tested: WordPress
2020
WordPress Plugin Strong Testimonials 2.40.0 – Persistent Cross-Site Scripting
The custom[client_name] and custom[company_name] parameters in the client details section of Strong Testimonials plugin in WordPress are vulnerable to stored cross-site scripting (XSS). This allows an attacker to execute malicious code on affected websites. The payload in custom[client_name] also gets executed in the All Testimonials page.
Mitigation:
Update to the latest version of Strong Testimonials plugin (2.41.0 or higher) which contains a patch for this vulnerability. Alternatively, remove the plugin if not needed.