Impact
The Affiliate Program Suite – SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross‑Site Scripting via attributes in the slicewp_affiliate_url shortcode. Shortcode attributes are not sanitized or escaped, allowing an authenticated user with contributor-level access or above to inject arbitrary JavaScript that will run when any page containing the shortcode is viewed. The flaw represents a classic client‑side injection weakness (CWE‑79) that can compromise user sessions, deface content, or serve malware.
Affected Systems
WordPress sites running the Affiliate Program Suite – SliceWP Affiliates plugin version 1.2.7 or earlier are affected. The vulnerability applies to all WordPress installations where the plugin is active and contributors or higher roles can create or edit content that includes the slicewp_affiliate_url shortcode.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate security impact. The attack requires authenticated access with at least contributor privileges; therefore it is not an open‑world vector but still poses a risk to sites with widely distributed or compromised contributor accounts. The absence of an EPSS score and the lack of a KEV listing suggest the flaw is not yet widely exploited, but the potential for client‑side script execution remains significant if an attacker can inject content.
OpenCVE Enrichment