CVE-2021-25078 Information

Description

The Affiliates Manager WordPress plugin before 2.9.0 does not validate sanitise and escape the IP address of requests logged by the click tracking feature allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://plugins.trac.wordpress.org/changeset/2648196 https://wpscan.com/vulnerability/d4edb5f2-aa1b-4e2d-abb4-76c46def6c6e

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: