Executive brief
The Affiliate Super Assistent WordPress plugin contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When users visit an affected page, the injected scripts execute in their browsers, enabling attackers to steal credentials, hijack accounts, or distribute malware to site visitors without authentication required.
Technical details
The vulnerability is a stored XSS flaw in the 'doCommentShortcode' function caused by insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary JavaScript code through user-controllable input that gets stored in the database. The malicious script persists and executes whenever any user accesses the affected page, making it a high-impact vulnerability. The issue affects all versions up to and including 1.10.2; patch status is not specified in the advisory.
Affected products
- WordPress Affiliate Super Assistent up to and including 1.10.2
Timeline
- 2026-09-01: disclosed