S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 18, 2025

CVE-2023-4284 Scanner

This scanner targets the timeline creation endpoint in the Post Timeline Plugin, where unsanitized input allows attackers to inject malicious scripts that execute in administrators' browsers.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4284
6.1
CVSS

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Post Timeline
AFFECTED< 2.2.6SAFE ✓≥ 2.2.6
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Post Timeline Plugin is a popular extension used by WordPress site administrators to add interactive timelines to their websites. This plugin is utilized predominantly on WordPress platforms and is often favored by content creators who aim to present chronological content in a visually engaging format. Its ease of use and integration capabilities make it a go-to choice for both beginner and experienced site designers. Due to its popularity and widespread use, ensuring the security of the Post Timeline Plugin is crucial to maintaining website integrity.

Cross-Site Scripting (XSS) is a common security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. In the context of WordPress Post Timeline Plugin, this vulnerability arises from improper sanitization of input fields. When exploited, it can allow attackers to execute arbitrary JavaScript code in the context of a site user's browser. This specific XSS vulnerability affects versions of the Post Timeline Plugin prior to 2.2.6.

The vulnerable endpoint is the timeline creation and editing functionality, specifically the 'post_timeline' parameter used in the admin panel. Attackers can inject malicious JavaScript through this parameter without proper validation or output encoding. The vulnerability is triggered when an administrator views or edits a timeline containing the crafted payload, leading to script execution in the WordPress admin dashboard.

If exploited, an attacker can steal session cookies, deface the website, redirect users to malicious sites, or perform actions on behalf of an administrator. This can lead to full site compromise, data theft, and loss of user trust. The CVSS score of 7.1 indicates a high severity, emphasizing the need for immediate remediation to protect WordPress installations using this plugin.

Solution Advice
  • Update the WordPress Post Timeline Plugin to version 2.2.6 or later to patch the vulnerability.
  • Implement input validation and sanitization on all user inputs within the WordPress environment.
  • Regularly check for updates to all plugins and themes to ensure vulnerabilities are promptly patched.
  • Conduct periodic security reviews and audits to detect and resolve potential vulnerabilities.
  • Consider deactivating and removing unused plugins to reduce the attack surface.
  • Use a Web Application Firewall (WAF) to block malicious payloads targeting XSS vulnerabilities.
  • Educate administrators on safe practices, such as avoiding clicking on suspicious links or entering untrusted data.
  • Enable Content Security Policy (CSP) headers to mitigate the impact of XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress Post Timeline XSS Scanner | S4E Free Check S4E