First published: Wed Mar 12 2025(Updated: )
The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Simple Affiliate | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2077 has a medium severity level due to its potential for reflected cross-site scripting (XSS) attacks.
To fix CVE-2025-2077, update the Simple Amazon Affiliate plugin to version 1.0.10 or later, which addresses the vulnerability.
Anyone using the Simple Amazon Affiliate plugin for WordPress versions up to and including 1.0.9 is affected by CVE-2025-2077.
CVE-2025-2077 is associated with reflected cross-site scripting (XSS) attacks.
Yes, unauthenticated attackers can exploit CVE-2025-2077 due to insufficient input sanitization in the affected plugin.