CVE-2023-47652
The Auto Affiliate Links plugin through version 6.4.2.4 contains a cross-site request forgery vulnerability because multiple functions including aalUpdateExcludePosts() lack proper nonce validation. An attacker could exploit this flaw by crafting a malicious request that, when clicked by an administrator, would allow the attacker to modify plugin settings and inject arbitrary JavaScript code into the site. The vulnerability requires social engineering to trick an administrator into clicking a link or visiting a malicious page.
Based on public CVE data (MITRE/NVD).