First published: Thu Dec 02 2021(Updated: )
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cbads Clickbank Affiliate Ads | <=1.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2015-20105.
CVE-2015-20105 has a severity rating of 9.6 (Critical).
The affected software is the ClickBank Affiliate Ads WordPress plugin version 1.20.
The vulnerability allows an attacker to make logged in admin change plugin settings and potentially perform Stored Cross-Site Scripting (XSS) attacks.
To fix CVE-2015-20105, update to a version of the ClickBank Affiliate Ads WordPress plugin that includes a CSRF check when saving settings and escapes output properly.