CVE-2023-46086: WordPress affiliate-toolkit – WordPress Affiliate Plugin Plugin <= 3.4.3 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin allows Reflected XSS.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-46086.
What is the severity of CVE-2023-46086?
CVE-2023-46086 has a severity rating of 7.1, which is considered high.
What is the affected software for CVE-2023-46086?
The affected software for CVE-2023-46086 is SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin versions up to and including 3.4.3.
What is the CWE category for CVE-2023-46086?
The CWE category for CVE-2023-46086 is CWE-79, which is a code injection vulnerability.
How can I fix CVE-2023-46086?
To fix CVE-2023-46086, update SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin to version 3.4.4 or later.