PT-2026-84104 · WordPress · Affiliate Super Assistent

·

CVE-2026-19573

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Affiliate Super Assistent versions prior to 1.10.3
Description Insufficient input sanitization and output escaping in the doCommentShortcode() function allow unauthenticated attackers to perform Stored Cross-Site Scripting. This enables the injection of arbitrary web scripts into pages, which execute when a user accesses the affected page.
Recommendations Update the plugin to a version later than 1.10.2. As a temporary workaround, consider disabling the doCommentShortcode() function until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19573

Affected Products

Affiliate Super Assistent