Impact
The Affiliate AI Lite plugin (WordPress) contains a stored XSS flaw in the 'asin' attribute of the affiai_img shortcode. Output is not properly escaped, allowing an attacker who can add or edit posts as a contributor or higher to embed malicious scripts that will run for any user viewing the page. The injected code can steal session cookies, deface content, or perform other malicious actions.
Affected Systems
The vulnerable plugin is rustaurius:Affiliate AI Lite for WordPress, affecting all releases up to and including version 1.0.1.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% shows a very low exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog, and would require an authenticated contributor‑level account to inject the payload. Exploitation typically occurs through normal content creation or editing functions of the shortcode, with the malicious code persisting server‑side and executing whenever a visitor loads the affected page.
OpenCVE Enrichment