Unrated severityNVD Advisory· Published Jul 2, 2014· Updated Jun 17, 2026
CVE-2014-4598
CVE-2014-4598
Description
Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the AID parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:wp-tmkm-amazon_project:wp-tmkm-amazon:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wp-tmkm-amazon_project:wp-tmkm-amazon:*:*:*:*:*:*:*:*range: <=1.5b
- (no CPE)range: <=1.5b
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.