2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] <= 2.1.5 (unfixed + closed)
unknown
[en] Reflected Cross-Site Scripting (XSS) vulnerability in 2kb Amazon Affiliates Store plugin <=2.1.5 on WordPress.
- Affected:
- up to 2.1.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 4, 2022
CVE-2022-40968 on NVD →
2kb Amazon Affiliates Store <= 2.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The 2kb Amazon Affiliates Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary we...
- CVSS:
- 5.5
- Affected:
- up to 2.1.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 24, 2022
CVE-2022-40968 on NVD →
2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] < 2.1.1 (closed)
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by Ricardo in WordPress 2kb Amazon Affiliates Store plugin (versions <=2.1.0).
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Sep 28, 2017
2kb Amazon Affiliates Store [2kb-amazon-affiliates-store] < 2.1.1 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Sep 27, 2017
CVE-2017-14622 on NVD →
2kb Amazon Affiliates Store < 2.1.1 - Reflected Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Sep 20, 2017
CVE-2017-14622 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database