PT-2025-52544 · WordPress · Amazon Affiliate Lite Plugin

Muhammad Afnaan

·

Published

2025-12-20

·

Updated

2025-12-20

·

CVE-2025-14734

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Amazon affiliate lite Plugin versions prior to 1.0.1
Description The Amazon affiliate lite Plugin for WordPress is susceptible to Cross-Site Request Forgery due to insufficient nonce validation within the ADAL settings page function. This allows attackers to potentially modify plugin settings by deceiving a site administrator into performing an action, such as clicking a malicious link. A successful attack requires the attacker to trick an administrator into performing an action.
Recommendations Update the Amazon affiliate lite Plugin to version 1.0.1 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-14734

Affected Products

Amazon Affiliate Lite Plugin