CVE-2024-9349

Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.2 - Reflected Cross-Site Scripting

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.


We have discovered 420 live websites that are affected by CVE-2024-9349.

Run a Free Instant Scan




Affected Software

Product  Amazon Auto Links
Category Wordpress Plugins
Vulnerable Domains420 live websites (19% of Amazon Auto Links install base)
Vulnerable Versions
  • from 0 through 5.4.2
Vulnerable Versions Count21 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 4, 2024
  • Updated - Oct 4, 2024

Credits

  • Dale Mavers (finder)

Website Distribution by Country

Number of websites using CVE-2024-9349
United States166 websites



Japan68 websites
Germany58 websites
GB20 websites
Italy18 websites
Cyprus17 websites
France17 websites
Spain7 websites
Brazil6 websites

Website Distribution by TLD

Number of websites using CVE-2024-9349
.com262 websites
.de33 websites
.net25 websites
.co.uk15 websites
.jp11 websites
.org11 websites
.it10 websites
.info8 websites
.fr6 websites
.at3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9349

Top websites that are affected by CVE-2024-9349. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
***********.com United States**,***
***********.com United States***,***
***********.org United States***,***
********.com United States***,***
****************.com United States***,***
*****.****.org United States***,***
******.**.jp Japan***,***
****************.net United States***,***
********.com United States***,***
See full domain list

FAQ

CVE-2024-9349 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Amazon Auto Links
A total of 420 websites have been identified as vulnerable to CVE-2024-9349, based on global website indexing conducted by WebTechSurvey.
The Amazon Auto Links is affected by the CVE-2024-9349 vulnerability.
Amazon Auto Links versions up to and including 5.4.2 are vulnerable to CVE-2024-9349.