AffiliateImporterEb WordPress plugin through 1.0.6 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin, exploit requires crafted request.
id: CVE-2024-12732
info:
name: AffiliateImporterEb <= 1.0.6 - Reflected XSS
author: Sourabh-Sah
...