CVE-2023-2178
Aajoda Testimonials < 2.2.2 - Admin+ Stored XSS
Record summary
CVE-2023-2178 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.
Description
The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Aajoda TestimonialsDefault status: unaffected | CVE List | Before 2.2.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAajoda Testimonials < 2.2.2 - Cross-Site ScriptingCVSS 4.8
The plugin does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Update Aajoda Testimonials plugin to version 2.2.2 or later to mitigate the vulnerability.
Source: ProjectDiscovery