First published: Thu Feb 01 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Michaeluno Auto Amazon Links Wordpress | <5.1.2 |
Update to 5.1.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52175 is classified as a high-severity vulnerability due to its potential for exploitation through stored cross-site scripting (XSS).
To mitigate CVE-2023-52175, users should update the Auto Amazon Links – Amazon Associates Affiliate Plugin to version 5.1.3 or later where the vulnerability has been fixed.
CVE-2023-52175 can be exploited through stored XSS attacks, allowing attackers to inject malicious scripts into web pages viewed by users.
CVE-2023-52175 affects users of the Auto Amazon Links – Amazon Associates Affiliate Plugin version 5.1.2 and earlier on WordPress installations.
If immediate updates are not feasible due to compatibility concerns, it is advised to implement additional security measures such as input sanitization or use an alternative plugin until an update is possible.