Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (CWE‑79) that enables an attacker to inject and execute arbitrary JavaScript in the victim’s browser by visiting a crafted URL on a WordPress site. The malicious script runs in the user’s session context, potentially allowing data disclosure or other unauthorized actions limited to that session. Based on the description, it is inferred that the attack vector involves a maliciously crafted URL that a victim accesses.
Affected Systems
WordPress sites that employ the wecantrack Affiliate Links Lite (Affiliate Links) plugin in any release up to and including version 3.1.0. No other products or vendors are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact. The EPSS score of < 1 % suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of reflected XSS, the likely attack vector involves a maliciously crafted URL that a victim accesses; this requires no special credentials or privileged access and exploits the plugin’s input handling flaw.
OpenCVE Enrichment
EUVD