Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mtdesigninfo

#51080of 53,632
4.3Total CVSS
Vulnerabilities · 1
PT-2014-6011
4.3
2014-07-02
WordPress · Wp-Tmkm-Amazon · CVE-2014-4598
**Name of the Vulnerable Software and Affected Versions** wp-tmkm-amazon plugin versions 1.5b and earlier **Description** The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `AID` parameter in the wp-tmkm-amazon-search.php file. **Recommendations** For wp-tmkm-amazon plugin versions 1.5b and earlier, avoid using the `AID` parameter in the affected API endpoint until the issue is resolved.