CVE-2023-4482

The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 198 live websites that are affected by CVE-2023-4482.

Run a Free Instant Scan




Affected Software

Product  Amazon Auto Links
Category Wordpress Plugins
Vulnerable Domains198 live websites (9.16% of Amazon Auto Links install base)
Vulnerable Versions
  • from 0 through 5.3.1
Vulnerable Versions Count13 versions ( 59% of all versions)



Details

  • Published - Oct 20, 2023
  • Updated - Feb 5, 2025

Credits

  • Marco Wotschka (finder)

Website Distribution by Country

Number of websites using CVE-2023-4482
United States78 websites



Japan30 websites
Germany28 websites
France9 websites
Cyprus8 websites
Spain7 websites
GB5 websites
Italy5 websites
Brazil3 websites

Website Distribution by TLD

Number of websites using CVE-2023-4482
.com122 websites
.de19 websites
.net14 websites
.org8 websites
.jp3 websites
.co.uk3 websites
.fr3 websites
.info3 websites
.it3 websites
.at2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-4482

Top websites that are affected by CVE-2023-4482. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
***********.com United States**,***
***********.com United States***,***
***********.org United States***,***
****************.net United States***,***
************.com United States***,***
*************.com Singapore*,***,***
*************.***.br Brazil*,***,***
****************.com United States*,***,***
*******************.com United States*,***,***
See full domain list

FAQ

A total of 198 websites have been identified as vulnerable to CVE-2023-4482, based on global website indexing conducted by WebTechSurvey.
The Amazon Auto Links is affected by the CVE-2023-4482 vulnerability.
Amazon Auto Links versions up to and including 5.3.1 are vulnerable to CVE-2023-4482.