CVE-2022-3897 Information
Dec 01, 2022
cve
Description
The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to and including 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Reference
https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3897 https://www.tipsandtricks-hq.com/wordpress-affiliate-platform-plugin-simple-affiliate-program-for-wordpress-blogsite-1474
Share on: