CVE-2024-49645 HIGH

CVE-2024-49645: WordPress Affiliate Platform plugin <= 1.4.8 - Reflected Cross Site Scripting (XSS) vulnerability

Vendor Ilias Gomatos
Product Affiliate Platform
Weakness CWE-79 · XSS
Published October 29, 2024
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform smdp-affiliate-platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through <= 1.4.8.

Explanation of Vulnerability in Simple Terms

02Summary

Affiliate Platform versions up to 1.4.8 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the application. An attacker can craft a malicious link that, when visited by a user, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or malware distribution. The vulnerability affects all users who click on attacker-controlled links.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in a user's browser to steal session data, credentials, or redirect to phishing sites.

Potential impact on your site

04Site Impact

Users visiting attacker-controlled links can have their sessions compromised or be redirected to malicious sites; site reputation may suffer.

Conditions required to exploit

05Prerequisites

Attacker must trick a user into clicking a malicious link (no authentication required to craft the payload).

Key dates

06Disclosure timeline

October 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE