Stored Cross-Site Scripting Vulnerability in SliceWP Affiliates Plugin for WordPress
CVE-2026-6672
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 May 2026
What is CVE-2026-6672?
The SliceWP Affiliates plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through its shortcode attributes. This vulnerability arises from inadequate input sanitization and output escaping for user-supplied entries within the 'slicewp_affiliate_url' shortcode. As a result, authenticated attackers with contributor-level access can inject malicious web scripts into pages, which are then executed when users access the compromised page. This presents a significant risk, necessitating immediate attention to ensure robust security measures are implemented.
Affected Version(s)
Affiliate Program Suite β SliceWP Affiliates 0 <= 1.2.7