CVE-2023-52175

WordPress Auto Amazon Links Plugin <= 5.1.1 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1.


We have discovered 64 live websites that are affected by CVE-2023-52175.

Run a Free Instant Scan




Affected Software

Product  Amazon Auto Links
Category Wordpress Plugins
Vulnerable Domains64 live websites (2.96% of Amazon Auto Links install base)
Vulnerable Versions
  • from 0 through 5.1.1
Vulnerable Versions Count9 versions ( 41% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 1, 2024
  • Updated - Aug 2, 2024

Credits

  • Tien Nguyen Anh (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2023-52175
United States23 websites



Japan12 websites
Germany8 websites
Spain5 websites
Brazil3 websites
GB3 websites
Cyprus2 websites
Singapore2 websites
Austria1 websites

Website Distribution by TLD

Number of websites using CVE-2023-52175
.com39 websites
.de4 websites
.net4 websites
.org4 websites
.com.br2 websites
.at1 websites
.co.jp1 websites
.co.uk1 websites
.es1 websites
.info1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-52175

Top websites that are affected by CVE-2023-52175. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
***********.org United States***,***
************.com United States***,***
*************.com Singapore*,***,***
*************.***.br Brazil*,***,***
****.******.net Japan*,***,***
*********.net Japan*,***,***
************.it Italy*,***,***
********.com Japan*,***,***
*********.com Cyprus*,***,***
See full domain list

FAQ

CVE-2023-52175 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Amazon Auto Links
A total of 64 websites have been identified as vulnerable to CVE-2023-52175, based on global website indexing conducted by WebTechSurvey.
The Amazon Auto Links is affected by the CVE-2023-52175 vulnerability.
Amazon Auto Links versions up to and including 5.1.1 are vulnerable to CVE-2023-52175.