First published: Thu Dec 02 2021(Updated: )
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cbads Clickbank Affiliate Ads | <=1.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-20106 is a vulnerability in the ClickBank Affiliate Ads WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
CVE-2015-20106 has a severity keyword of medium and a severity value of 4.8.
CVE-2015-20106 affects the ClickBank Affiliate Ads WordPress plugin through version 1.20.
Even when the unfiltered_html is disallowed, CVE-2015-20106 can still allow high privilege users to perform Cross-Site Scripting attacks.
You can find more information about CVE-2015-20106 at this reference: https://wpscan.com/vulnerability/907792c4-3384-4351-bb75-0ad10f65fbe1