CVE-2021-25078
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing…
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wpaffiliatemanager/affiliates manager
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2648196Patch, Third Party Advisory
- https://wpscan.com/vulnerability/d4edb5f2-aa1b-4e2d-abb4-76c46def6c6eExploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2648196Patch, Third Party Advisory
- https://wpscan.com/vulnerability/d4edb5f2-aa1b-4e2d-abb4-76c46def6c6eExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.