WordPress Coupon Affiliates Plugin <= 5.4.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30475

7.1HIGH

What is CVE-2023-30475?

An unauthenticated reflected Cross-Site Scripting (XSS) vulnerability was identified in RelyWP's WooCommerce Affiliate Plugin, specifically in versions 5.4.5 and earlier. This security flaw could potentially allow attackers to inject malicious scripts into web pages viewed by users, resulting in unauthorized actions or information leaks. It's crucial for users of the affected plugin to apply security updates promptly to mitigate this risk and protect their sites from potential exploitation.

Affected Version(s)

WooCommerce Affiliate Plugin – Coupon Affiliates <= 5.4.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivy - TOOR, LISA (Patchstack Alliance)
.