Executive brief
The AAWP plugin for WordPress, which is used to integrate Amazon Affiliate products into websites, contains a security flaw that allows attackers to run malicious code in a user's browser. By tricking an authenticated user into clicking a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on the website. This could lead to a compromise of the site's administrative functions or the theft of sensitive user data.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the AAWP plugin for WordPress (version 3.16 and potentially earlier) due to improper neutralization of the 'tab' parameter in the 'aawp-settings' admin page. An authenticated attacker can exploit this by crafting a malicious URL containing a JavaScript payload and tricking another authenticated user into visiting it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. The vulnerability is tracked as CWE-79 and has a proof-of-concept available in public exploit databases.
Affected products
- Getaawp AAWP 3.16
Timeline
- 2022-01-04: other: Vulnerability discovered and exploit authored
- 2022-01-05: disclosed: Exploit published on Exploit-DB
- 2026-05-10: advisory: NVD and VulnCheck advisory published