Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-09-27T17:00:00
Updated: 2024-08-05T19:34:38.636Z
Reserved: 2017-09-20T00:00:00
Link: CVE-2017-14622
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-09-28T01:29:01.653
Modified: 2024-11-21T03:13:13.400
Link: CVE-2017-14622
Redhat
No data.