Impact
The Affiliate Super Assistent plugin for WordPress contains a stored cross‑site scripting flaw in the doCommentShortcode function. The function constructs and stores user‑supplied content without sufficient input sanitization or output escaping. As a result, unauthenticated attackers can inject arbitrary JavaScript that will execute whenever a victim views a page containing the injected comment. This type of vulnerability can allow attackers to hijack user sessions, deface the site, or redirect users to malicious destinations.
Affected Systems
WordPress sites running the worschtebrot Affiliate Super Assistent plugin, with any installed version up to and including 1.10.2. The vulnerability affects any instance where the doCommentShortcode feature is enabled and used within the site.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium severity risk, with the attack vector being a web-based unauthenticated user. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation to date. Nonetheless, the flaw permits cross‑site scripting that can be leveraged by attackers to compromise user accounts or deface content. An attacker needs only to submit malicious input via the public comment interface, and the injected script will run for future visitors without further interaction.
OpenCVE Enrichment