Executive brief
A security vulnerability exists in the Affiliate Super Assistent plugin for WordPress, which is used to manage Amazon affiliate products. An attacker can inject malicious scripts into the website that execute when other users or administrators view certain pages. This could lead to unauthorized actions being performed in a user's session, theft of sensitive information, or website defacement.
Technical details
The Affiliate Super Assistent (amazonsimpleadmin) plugin for WordPress suffers from a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation (CWE-79). This flaw allows an unauthenticated remote attacker to inject persistent malicious scripts into the application. The vulnerability is triggered when a user with higher privileges, such as an administrator, interacts with the affected page. According to the CVSS vector, the attack requires user interaction but can result in a scope change, potentially allowing the attacker to access session cookies or perform actions on behalf of the victim. The issue affects all versions through 1.10.1.
Affected products
- Timo Affiliate Super Assistent (amazonsimpleadmin) <= 1.10.1
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory