Amazon Link <= 3.2.10 - Authenticated (Admin+) Cross-Site Scripting
mediumThe Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
- CVSS:
- 6.1
- Affected:
- up to 3.2.10
- Fix:
- No patched version reported
- Disclosed:
- May 9, 2022