Impact
Unauthenticated Cross Site Scripting vulnerability exists in the AffiliateWP plugin for WordPress versions 2.35.0 and earlier. The flaw allows an attacker to inject malicious script into web pages served by the plugin, potentially hijacking user sessions, defacing websites, or stealing credentials. The weakness corresponds to CWE‑79 and can affect the confidentiality, integrity, and availability of the affected environment.
Affected Systems
The vulnerability impacts the AffiliateWP WordPress plugin provided by AffiliateWP. All installations of AffiliateWP versions 2.35.0 or earlier are affected. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity level. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw from any network, as authentication is not required. The likely attack vector is through unsanitized user input that is rendered on the site, making exploitation straightforward for anyone who can access the site’s pages.
OpenCVE Enrichment