Super Testimonials Plugin Stored Cross-Site Scripting Vulnerability (CVE-2023-5613) — Medium Severity

WordPress users, particularly those relying on the Super Testimonials plugin, should be aware of a security vulnerability identified as CVE-2023-5613. This flaw involves a type of attack called Stored Cross-Site Scripting (XSS), which could allow malicious scripts to run on your website.

In simple terms, the Super Testimonials plugin, specifically through its ‘tpsscode’ shortcode, didn’t properly clean up or secure certain user-provided information. This oversight meant that an attacker who had access to your WordPress site (even with common contributor-level permissions) could inject harmful code. Once injected, this code would then automatically execute in the browsers of other users visiting the affected pages.

This kind of vulnerability can lead to various issues, including unauthorized data access, session hijacking, or defacing a website. Keeping your plugins updated and understanding potential risks like this is crucial for maintaining a secure WordPress environment.

CVE Details

Product: Super Testimonials plugin for WordPress

Published: October 20, 2023

Severity: Medium

Status: Analyzed

Affected Products

The Stored Cross-Site Scripting vulnerability impacts all versions of the Super Testimonials plugin for WordPress up to, and including, version 2.9.

Current Status

This vulnerability, identified as CVE-2023-5613, has been fully analyzed. This means that its nature, scope, and potential impact are understood by security researchers.

Severity Level

The vulnerability carries a Medium severity rating. While it requires an authenticated attacker (meaning someone needs to be logged into your WordPress site with at least contributor permissions), the potential for injecting arbitrary web scripts makes it a significant concern. Successfully exploiting an XSS flaw can compromise user sessions, redirect visitors to malicious sites, or steal sensitive information.

Possible Solutions

To protect your WordPress site from this vulnerability, it is crucial to update the Super Testimonials plugin to a patched version. Based on the vulnerability details, all versions up to and including 2.9 are affected. Therefore, users should look for an update beyond version 2.9. It is highly recommended to update to the latest available version of the Super Testimonials plugin as soon as possible. Always back up your website before performing any plugin updates.

If an immediate update is not feasible, consider temporarily deactivating the plugin until you can apply the patch, or restrict user roles that have access to edit posts and pages where the ‘tpsscode’ shortcode could be utilized.

References

https://plugins.trac.wordpress.org/browser/super-testimonial/tags/2.8/tp-testimonials.php#L214

https://plugins.trac.wordpress.org/changeset/2979378/super-testimonial#file9

https://www.wordfence.com/threat-intel/vulnerabilities/id/52659f1c-642e-4c88-b3d0-d5c5a206b11c?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.