S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 16, 2024

CVE-2017-18558 Scanner

CVE-2017-18558 scanner - Cross-Site Scripting (XSS) vulnerability in Testimonials plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18558
6.1
CVSS

The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The bws-testimonials plugin is a popular tool used to display client feedback on WordPress-based websites. This plugin has been praised for its ease of use and customization options, making it a go-to for businesses looking to showcase their success stories. However, the security of this plugin has recently been called into question due to the discovery of several vulnerabilities, including CVE-2017-18558.

CVE-2017-18558 is a cross-site scripting (XSS) vulnerability located in the Testimonials shortcode, which can be exploited by attackers to execute malicious code on a user's browser. This vulnerability can be triggered by inserting specially crafted JavaScript code into the plugin's input fields, such as the name and message fields.

Such an exploit could result in a range of consequences, including redirecting users to malicious websites, stealing sensitive information, or installing malware. Moreover, as this plugin is often used on business websites, attackers could use it to gain access to corporate networks or other valuable digital assets.

In conclusion, while the Testimonials plugin can be a valuable tool for businesses to showcase their successes, it is important to be aware of the potential risks associated with it. By following the recommended precautions and partnering with a trusted security provider like s4e.io, website owners can remain ahead of the curve and minimize the risk of damaging cyberattacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several best practices that website owners should follow:

  • Keep the plugin up to date with the latest version.
  • Implement input sanitization and validation techniques to filter out malicious code.
  • Use web application firewalls (WAFs) to block known XSS attacks.
  • Educate users on safe browsing habits, such as not clicking on suspicious links or messages.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18558 scanner - Cross-Site Scripting (XSS) vulnerability in Testimonials plugin for WordPress S4E