CVE-2025-11451 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4…
High CVSS: 7.5

CVE-2025-11451

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Vendor
-
Product
-
CWE
CWE-73
Yayın Tarihi
2025-11-11 04:15:41
Güncelleme
2025-11-12 16:19:59
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar