Executive brief
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress, which helps site owners display Amazon affiliate content, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other visitors or administrators view these pages, the scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'adid' shortcode attribute. This vulnerability exists in all versions up to and including 1.1. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a post or page using the shortcode. These scripts will then execute in the browser of any user who visits the affected page. The vulnerability is classified as CWE-79 and has a CVSS base score of 6.4, reflecting that while it requires authentication, it can impact the integrity and confidentiality of user sessions.
Affected products
- WP Iframe Geo Style for Amazon affiliates WP Iframe Geo Style for Amazon affiliates Up to, and including, 1.1
Timeline
- 2026-05-27: disclosed: Initial disclosure date
- 2026-05-27: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/wp-iframe-geo-style-for-amazon-affiliates/trunk/index.php
- https://plugins.trac.wordpress.org/browser/wp-iframe-geo-style-for-amazon-affiliates/trunk/index.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/030d65bb-ec5b-4d26-8f59-5db9a9005ba6?source=cve