CVE-2025-11451: Miunosoft Auto Amazon Links – Amazon Associates Affiliate Plugin
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected products
- Miunosoft Auto Amazon Links – Amazon Associates Affiliate Plugin: up to and including 5.4.3
Published 2025-11-11. Last modified 2026-06-17.