{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/affiliate-super-assistent--1.10.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:affiliate_super_assistent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-19573"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Affiliate Super Assistent (\u003c= 1.10.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Affiliate Super Assistent plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) flaw identified as CVE-2026-19573. The issue exists within the ‘doCommentShortcode’ function, which fails to properly sanitize user-supplied input or escape output before rendering it in the browser. An unauthenticated attacker can leverage this weakness to inject malicious JavaScript into web pages served by the plugin. When a legitimate user or administrator views an affected page, the injected script executes within the victim's session, potentially leading to unauthorized actions, session hijacking, or the defacement of the site. This vulnerability affects all versions of the Affiliate Super Assistent plugin up to and including 1.10.2. Defending against this threat requires immediate patching or removal of the vulnerable plugin, as the lack of input sanitization provides a direct vector for script injection.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who visits the compromised page. This can lead to account takeover, the redirection of users to malicious domains, or the theft of sensitive session cookies. Given the nature of Stored XSS, these attacks persist until the malicious payload is manually removed from the database or the underlying vulnerability is remediated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Affiliate Super Assistent plugin to a version released after 1.10.2 to remediate CVE-2026-19573.\u003c/li\u003e\n\u003cli\u003eAudit database content associated with the Affiliate Super Assistent plugin for suspicious script tags or obfuscated JavaScript.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at endpoints responsible for comment submissions or form processing utilized by the plugin.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T07:03:27Z","date_published":"2026-09-01T07:03:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-01-cve-2026-19573/","summary":"The Affiliate Super Assistent plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the doCommentShortcode function, allowing unauthenticated attackers to execute arbitrary scripts in the context of a victim's session.","title":"Stored Cross-Site Scripting Vulnerability in Affiliate Super Assistent WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-01-cve-2026-19573/"}],"language":"en","title":"CraftedSignal Threat Feed - Affiliate Super Assistent (\u003c= 1.10.2)","version":"https://jsonfeed.org/version/1.1"}