A security flaw has been found in the Themepoints Super Testimonials plugin for WordPress, specifically affecting versions 2.6 and older. This vulnerability, identified as a Stored Cross-Site Scripting (XSS) issue, could allow an attacker to inject harmful scripts into your website. Because it requires an authenticated administrator-level user to perform an action, its impact is rated as Medium severity.
Cross-Site Scripting vulnerabilities are a common type of web security problem. In this specific case, a malicious actor, if they gain administrator-level access or trick an existing admin, could insert code that then runs in the browsers of your website visitors. This could lead to various unwelcome outcomes, such as defacing your site, redirecting users to other pages, or stealing sensitive information like session cookies.
CVE Details
Product Name: Themepoints Super Testimonials Plugin
Published Date: October 28, 2022
Severity: Medium
Status: Analyzed
Affected Products
The vulnerability impacts Themepoints Super Testimonials Plugin versions up to and including 2.6. If you are using this plugin on your WordPress site and your version is 2.6 or earlier, your site is at risk.
Current Status
This vulnerability has been thoroughly analyzed. A fix has been released by the plugin developers to address the issue. Site administrators are strongly advised to take action to secure their installations.
Severity Level
The vulnerability has been assigned a CVSS score of 4.8, categorizing it as Medium severity. While an attacker needs to have at least administrator privileges (or trick an administrator into taking action) to exploit this, the potential consequences of a successful XSS attack can be significant. It means an attacker could potentially manipulate content, hijack user sessions, or redirect visitors, undermining your website’s integrity and trustworthiness.
Possible Solutions
The most important step to protect your website is to update the Themepoints Super Testimonials Plugin immediately. The issue has been resolved in version 2.7. Therefore, upgrading to version 2.7 or any later version will patch this security hole.
Always ensure your WordPress plugins are kept up-to-date. Regular updates often include crucial security fixes that protect your site from known vulnerabilities.
References
https://patchstack.com/database/vulnerability/super-testimonial/wordpress-testimonials-plugin-2-6-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress
https://patchstack.com/database/vulnerability/super-testimonial/wordpress-testimonials-plugin-2-6-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress


