Impact
The vulnerability allows an attacker to inject malicious JavaScript code that is stored by the plugin and later rendered on the website. When a user visits a page that displays the stored content, the code runs in the victim’s browser, potentially stealing session data, credentials, or manipulating the page. This results in a severe compromise of confidentiality and integrity for all users who view the affected content.
Affected Systems
On WordPress installations running the Affiliate Link Tracker plugin from any version up through 0.2 by SEOSEON EUROPE S.L. No specific WordPress core versions are mentioned, so any site with the affected plugin is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests that real‑world exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. However, the display of stored malicious code can still be leveraged for phishing, credential theft, or further attacks against site visitors. The attack requires the attacker to supply input through the plugin’s data entry interface, which means administrative access or the ability to submit data to the plugin is needed. All users who view the stolen content are potentially affected.
OpenCVE Enrichment