CVE-2022-50970
The Amazon Affiliate plugin for WordPress contains a reflected cross-site scripting flaw affecting version 3.17 and earlier through the 'tab' parameter, which lacks proper input validation and output encoding. An unauthenticated attacker could exploit this vulnerability by crafting a malicious link that, when clicked by a user, executes arbitrary JavaScript code in the victim's browser. The vulnerability requires social engineering to trick a user into interacting with a specially crafted URL.
Based on public CVE data (MITRE/NVD).