S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 8, 2026

CVE-2024-12732 Scanner

CVE-2024-12732 Scanner - Cross-Site Scripting (XSS) vulnerability in AffiliateImporterEb

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-12732
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
AffiliateImporterEb
0
Updated Aug 22, 2026View on NVD →
Detail

AffiliateImporterEb is a WordPress plugin used by websites that integrate affiliate marketing efforts. Web administrators and marketing professionals employ this plugin to streamline the import process of affiliate products into their websites, leveraging it to enhance affiliate marketing campaigns. This tool is mainly utilized in e-commerce platforms or sites featuring product listings, helping users capitalize on affiliate product data. Additionally, AffiliateImporterEb supports various affiliate networks, simplifying product import/export processes. Moreover, it is popular for its versatility and ease of use. The plugin is often updated to meet the evolving demands of digital marketing strategies.

The Cross-Site Scripting (XSS) vulnerability in AffiliateImporterEb occurs when unsanitized and unescaped parameter output allows attackers to execute scripts in the context of a user's browser. This vulnerability specifically targets admin users, who have high privileges, making the exploitation more severe. The attack can be initiated through a crafted request, potentially compromising the admin's account. As a result, unauthorized actions may be performed by the attacker. XSS vulnerabilities are critical as they can lead to widespread security issues within applications. It is essential to address such threats promptly to maintain the integrity and confidentiality of web applications.

The vulnerability lies in the way AffiliateImporterEb processes unsanitized parameters in its settings page URL. Specifically, the vulnerable endpoint is `wp-admin/admin.php?page=ebdn-settings&module` with the parameter accepting unsanitized input data. By crafting requests that include scripts, an attacker can execute arbitrary code. This tactic exploits the absence of proper input sanitization and output encoding. Successful exploitation returns HTTP 200 status code, confirming the execution. The attack can be observed by the presence of the script in the response body, verifying the vulnerability.

When this XSS vulnerability is exploited, malicious actors gain the ability to execute arbitrary scripts within the admin's browser session. This can lead to various consequences, including session hijacking, unauthorized transactions, and data breaches. Admin accounts could be compromised, allowing attackers to modify site settings or content. Furthermore, sensitive information could be exposed, leading to potential financial losses and reputational damage for affected businesses. The presence of such vulnerabilities threatens the overall security posture of the application and its users.

REFERENCES

Solution Advice
  • Update AffiliateImporterEb to a version later than 1.0.6 to patch the vulnerability.
  • Implement proper input validation and output encoding to prevent XSS attacks in the future.
  • Conduct regular security audits and utilize security plugins to monitor potential threats.
  • Consider disabling or limiting the execution of code in browser settings to mitigate XSS risks.
  • Educate administrators and users about the risks associated with XSS and how to avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.