plugin

2Kb Amazon Affiliates Store Vulnerabilities

5 known security issues reported for the 2Kb Amazon Affiliates Store WordPress plugin. Most recent disclosed Dec 4, 2022.

2 medium

Running 2Kb Amazon Affiliates Store on your site? Check whether your installed version is affected.

Scan your site free

2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] <= 2.1.5 (unfixed + closed)

unknown

[en] Reflected Cross-Site Scripting (XSS) vulnerability in 2kb Amazon Affiliates Store plugin <=2.1.5 on WordPress.

Affected:
up to 2.1.5
Fix:
No patched version reported
Disclosed:
Dec 4, 2022

CVE-2022-40968 on NVD →

2kb Amazon Affiliates Store <= 2.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The 2kb Amazon Affiliates Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary we...

CVSS:
5.5
Affected:
up to 2.1.5
Fix:
No patched version reported
Disclosed:
Oct 24, 2022

CVE-2022-40968 on NVD →

2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] < 2.1.1 (closed)

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Ricardo in WordPress 2kb Amazon Affiliates Store plugin (versions <=2.1.0).

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Sep 28, 2017

2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] < 2.1.1 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.

Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Sep 27, 2017

CVE-2017-14622 on NVD →

2kb Amazon Affiliates Store < 2.1.1 - Reflected Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 2.1.1
Fixed in:
2.1.1
Disclosed:
Sep 20, 2017

CVE-2017-14622 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database