Vulnerability Description
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(), where the stored value is echoed directly into an anchor element's href attribute and inner text without esc_url(), esc_attr(), or esc_html(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the admin statistics page that execute in an administrator's browser when the page is visited, leveraging a publicly exposed nonce and an unauthenticated AJAX endpoint registered via the wp_ajax_nopriv_ hook.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.6/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.6/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.6/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.8/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.8/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/tags/6.8.8/aa
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/trunk/aal_sta
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/trunk/aal_sta
- https://plugins.trac.wordpress.org/browser/wp-auto-affiliate-links/trunk/aal_sta
- https://plugins.trac.wordpress.org/changeset/3519003/wp-auto-affiliate-links/tru
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-auto-affiliate-links
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6c8ed84e-3504-42e3-821
FAQ
What is CVE-2026-7330?
CVE-2026-7330 is a vulnerability with a CVSS score of 7.2 (HIGH). The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST para...
How severe is CVE-2026-7330?
CVE-2026-7330 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7330?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.