Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. An attacker can inject malicious JavaScript into data fields handled by the Affiliate Super Assistent plugin, and that script will execute when any user views the affected page.
Affected Systems
All WordPress sites that have installed the Affiliate Super Assistent plugin by Timo with a version up to and including 1.10.1 are affected. The flaw applies to any installation that has not yet applied the vendor’s patch that addresses the XSS issue.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so current exploitation prevalence is unknown. The stored XSS can be triggered through the plugin’s input mechanisms, enabling a remote attacker to execute arbitrary scripts in the browsers of site visitors. Given the ubiquity of WordPress installations, the attack surface is considerable, making timely remediation essential.
OpenCVE Enrichment