S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 11, 2024

CVE-2017-14622 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in 2kb Amazon Affiliates Store plugin for WordPress affects v. before 2.1.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-14622
6.1
CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The 2kb Amazon Affiliates Store plugin is a popular WordPress plugin used by many website owners to generate income through Amazon's affiliate program. This plugin allows users to easily create an Amazon product store on their website, with customizable templates and product displays. It is widely used by bloggers, marketers, and e-commerce stores to monetize their content and drive sales through Amazon.

However, the plugin has been found to have multiple cross-site scripting (XSS) vulnerabilities, including CVE-2017-14622. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the page or kbAction parameters in the kbAmz page to wp-admin/admin.php. Hackers can exploit this vulnerability to execute scripts on the website, steal sensitive information like user credentials, and even take over the entire website.

If this vulnerability is successfully exploited, it can have devastating consequences for website owners. Attackers can use it to gain unauthorized access to the website and its data, deface the website, or even use it as a launchpad for attacks against other websites and networks. Moreover, it can severely damage the reputation of the website and its owner, leading to loss of business and trust among customers.

If website owners are not sure about the security of their digital assets, they can rely on the s4e.io platform to quickly and easily scan and identify vulnerabilities in their websites, applications, and networks. With pro features like vulnerability scanning, automatic updates, and expert advice, website owners can rest assured that their digital assets are secure and protected against the latest threats and attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take several precautions, including:

  • Updating the affected plugin to the latest version as soon as possible.
  • Enabling automatic updates for all WordPress plugins and themes to ensure timely patching of vulnerabilities.
  • Installing a web application firewall (WAF) to block malicious traffic and filter out XSS payloads.
  • Implementing a Content Security Policy (CSP) to restrict the types of scripts that can run on the website.
  • Educating website users and administrators about XSS attacks and best practices for secure browsing.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-14622 scanner - Cross-Site Scripting (XSS) vulnerability in 2kb Amazon Affiliates Store plugin for WordPress | S4E