Impact
Unauthenticated reflected Cross Site Scripting is present in AffiliateWP plugin versions 2.34.0 and older. The flaw allows an attacker to inject arbitrary JavaScript into a page that the plugin renders after reflecting user‑supplied data. Once executed, the script can steal session or authentication cookies, track user interactions, or perform actions on the victim’s behalf, thereby compromising confidentiality and integrity of the client‑side environment. This weakness is categorized as CWE‑79.
Affected Systems
WordPress sites that utilize the AffiliateWP plugin version 2.34.0 or any earlier release. No other vendors or versions are affected. The plugin’s distribution channel is AffiliateWP.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity level. The EPSS score of less than 1% shows that, as of this analysis, exploitation likelihood is low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers likely trigger the reflected XSS by crafting URLs or input that the plugin echoes back to the browser. Authentication is not required, so any visitor can reach the vulnerable code through the public website.
OpenCVE Enrichment