CVE-2022-4794: Getaawp Amazon Affiliate WordPress Plugin

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

Affected products

  • Getaawp Amazon Affiliate WordPress Plugin: before 3.12.3 (fixed in 3.12.3)

Published 2023-01-30. Last modified 2026-06-17.