Description
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Problem types
CWE-73 External Control of File Name or Path
Product status
* (semver)
Timeline
| 2025-11-10: | Disclosed |
Credits
Rafshanzani Suhada
References
www.wordfence.com/...-400d-45ea-8a96-1669b0694d70?source=cve
plugins.trac.wordpress.org/...nAutoLinks_UnitOutput_Base.php
plugins.trac.wordpress.org/...s_UnitOutput__TemplatePath.php