VYPR

Amazon affiliate lite Plugin

by WordPress

CVEs (2)

  • CVE-2025-14734MedDec 20, 2025
    risk 0.35cvss 5.4epss 0.00

    The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the 'ADAL_settings_page' function. This makes it possible for unauthenticated…

  • CVE-2025-14735MedDec 20, 2025
    risk 0.29cvss 4.4epss 0.00

    The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…