Executive brief
The AzonPost plugin for WordPress, which is used to manage Amazon affiliate content, contains a security flaw that allows attackers to run malicious scripts in a user's browser. To exploit this, an attacker must trick a site administrator into clicking a specially crafted link. If successful, the attacker could potentially gain unauthorized access to the website's administrative session or perform actions on behalf of the administrator.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the AzonPost WordPress plugin due to insufficient input sanitization and output escaping of the 'editpos_hidden' parameter. The flaw is located within the 'azonpost-campaign.php' file. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a script payload and persuading a privileged user, such as an administrator, to visit the link. Upon execution, the script runs within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. The vulnerability affects all versions of the plugin up to and including 1.3.
Affected products
- AzonPost AzonPost Up to and including 1.3
Timeline
- 2026-05-12: advisory: Vulnerability published by Wordfence and NVD.