CVE · Medium

CVE-2022-50970 — AAWP [aawp] < 3.17.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50970 AAWP [aawp] < 3.17.1 Medium 5.4 < 3.17.1 3.17.1 2022-01-04

CVE-2022-50970

The Amazon Affiliate plugin for WordPress contains a reflected cross-site scripting flaw affecting version 3.17 and earlier through the 'tab' parameter, which lacks proper input validation and output encoding. An unauthenticated attacker could exploit this vulnerability by crafting a malicious link that, when clicked by a user, executes arbitrary JavaScript code in the victim's browser. The vulnerability requires social engineering to trick a user into interacting with a specially crafted URL.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.