Stored Cross-Site Scripting Vulnerability in Affiliate Reviews Plugin for WordPress
CVE-2025-5845
6.4MEDIUM
What is CVE-2025-5845?
The Affiliate Reviews plugin for WordPress suffers from a vulnerability that allows authenticated attackers to inject arbitrary web scripts via the ânumColumnsâ parameter. This is due to inadequate input sanitization and output escaping measures in versions up to and including 1.0.6. Attackers with Contributor-level access and above can exploit this flaw to manipulate pages viewed by users, leading to potential execution of malicious scripts.
Affected Version(s)
Affiliate Reviews * <= 1.0.6