Back to VulnFeed / CVE-2026-7330
root@hackertop:~/vulnfeed/CVE-2026-7330#
CVE-2026-7330 MEDIUM CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

thedark Auto Affiliate Links Plugin up to 6.8.8 on WordPress AJAX Endpoint aal_url_stats_save_action url cross site scripting

Auto Affiliate Links Plugin 13d ago Impact pending confirmation
LIFECYCLE
5.6 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in thedark Auto Affiliate Links Plugin up to 6.8.8 on WordPress (Advertising Software). It has been declared as problematic. This vulnerability affects the function aal_url_stats_save_action of the component AJAX Endpoint. Upgrading to version 6.8.6 eliminates this vulnerability.
Root Cause Analysis
The manipulation of the argument url with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-79. The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Impact: As an impact it is known to affect integrity.

Countermeasure: Upgrading to version 6.8.6 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7330 · CVSS 5.6 · Active Threat