CVE-2014-4577: Websupporter Wp Amasin - The Amazon Affiliate Shop

Medium severity, CVSS 5.0. EPSS: 3.7% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.

Affected products

  • Websupporter Wp Amasin - The Amazon Affiliate Shop: up to and including 0.9.6

Published 2014-10-21. Last modified 2026-06-17.