The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
History

Wed, 12 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Miunosoft
Miunosoft auto Amazon Links Amazon Associates Affiliate Plugin
Wordpress
Wordpress wordpress
Vendors & Products Miunosoft
Miunosoft auto Amazon Links Amazon Associates Affiliate Plugin
Wordpress
Wordpress wordpress

Tue, 11 Nov 2025 03:45:00 +0000

Type Values Removed Values Added
Description The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Title Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-11-11T03:30:39.282Z

Updated: 2025-11-12T20:07:20.166Z

Reserved: 2025-10-07T16:53:27.994Z

Link: CVE-2025-11451

cve-icon Vulnrichment

Updated: 2025-11-12T16:07:57.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T04:15:41.433

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-11451

cve-icon Redhat

No data.