WordPress security by component
AffiliateX – Amazon Affiliate Plugin
Plugin description
AffiliateX – Amazon Affiliate Plugin is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jan 15, 2026; the highest published CVSS base score is 6.4.
Plugin slug:
affiliatex-amazon-affiliate-pluginLatest vulnerability
CVE-2025-13859: AffiliateX – Amazon Affiliate Plugin: Cross-site scripting
AffiliateX – Amazon Affiliate Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jan 15, 2026 |
CVE-2025-13859
AffiliateX – Amazon Affiliate Plugin: Cross-site scripting
AffiliateX – Amazon Affiliate Plugin is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|