Impact
The TBTestimonials plugin for WordPress hosts an Improper Neutralization of Input During Web Page Generation flaw, classified as CWE‑79, that permits a reflected XSS attack. A crafted request containing malicious payload can be echoed back by the plugin to the visitor’s browser, enabling script execution within the site’s context. Based on the description, the vulnerability is specifically related to input captured in testimonial or banner fields that is not properly sanitized before rendering.
Affected Systems
WordPress sites that have installed the TBTestimonials plugin version 1.7.3 or earlier, from the plugin’s initial release through 1.7.3. Any environment running those versions is susceptible if the testimonial or banner fields are not properly sanitized.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity risk. The EPSS score of less than 1 % indicates that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. The likely attack vector is inferred to be a public URL or form that incorporates user‑controlled input in the testimonial or banner fields; an attacker can embed malicious content in such input which the plugin then reflects back to the victim’s browser, enabling the execution of the supplied script.
OpenCVE Enrichment
EUVD