A notable security flaw, identified as CVE-2022-3539, has been found in the Super Testimonials WordPress plugin, including both its free and Pro versions. This vulnerability allows an attacker to inject harmful scripts into a website, potentially affecting how the site functions for its users.
This particular issue is a type of Cross-Site Scripting (XSS) attack. It means that if you are a high-privilege user, like an administrator, you could inadvertently trigger this vulnerability even if your WordPress settings normally prevent unfiltered HTML content. The attacker could use specially crafted input in areas like the “Position” or “Testimonial Text” fields to execute malicious code within your browser or the browsers of other users who view the affected content.
CVE Details
- Product: Super Testimonials WordPress Plugin
- CVE ID: CVE-2022-3539
- Published: November 14, 2022
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts the following versions of the Super Testimonials WordPress plugin:
- Super Testimonials WordPress plugin: All versions before 2.7 (free)
- Super Testimonials Pro WordPress plugin: All versions before 1.0.8 (paid)
Users running these older versions are at risk and should take immediate action to secure their websites.
Current Status
This vulnerability has been officially analyzed. This means security researchers have confirmed its existence and understand its potential impact. While the details are public, active exploitation of this specific vulnerability might still occur if websites are not updated.
Severity Level
The vulnerability is rated with a Medium severity (CVSS score of 4.8). A medium severity rating indicates that while an attack requires specific conditions, it could lead to moderate damage if exploited. In this case, an attacker could potentially steal sensitive information, deface the website, or redirect users to malicious sites, especially impacting administrative users and visitors to pages displaying testimonials.
Possible Solutions
The good news is that fixes are available for this vulnerability. To protect your WordPress site, follow these critical steps:
- Update the Free Plugin: If you are using the free Super Testimonials WordPress plugin, update to version 2.7 or later immediately.
- Update the Pro Plugin: If you are using the Super Testimonials Pro WordPress plugin, update to version 1.0.8 or later immediately.
Always ensure your WordPress core, themes, and all other plugins are kept up-to-date to benefit from the latest security patches. Regularly backing up your website is also a crucial security practice.
References
- https://wpscan.com/vulnerability/ab3b0052-1a74-4ba3-b6d2-78cfe56029db
- https://wpscan.com/vulnerability/ab3b0052-1a74-4ba3-b6d2-78cfe56029db


