WordPress Plugin Vulnerable to Reflected Cross-Site Scripting

CVE-2024-5281
Currently unrated 🤨

Key Information

Vendor
WordPress
Status
WP-affiliate-platform
Vendor
CVE Published:
13 July 2024

Summary

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected Version(s)

wp-affiliate-platform < 6.5.1

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Bob Matyas
WPScan
.