Medium severity6.4NVD Advisory· Published Oct 20, 2023· Updated Apr 8, 2026
CVE-2023-4482
CVE-2023-4482
Description
The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected products
1- cpe:2.3:a:michaeluno:auto_amazon_links:*:*:*:*:*:wordpress:*:*Range: <5.3.2
Patches
16e71febebc59Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/11ffb8a1-55d2-44c5-bcd2-ba866b94e8bcnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.