Input validation vulnerability in No API Amazon Affiliate 4.2.2

The No API Amazon Affiliate plugin for WordPress is not secure in versions 4.2.2 and earlier. This means that people with administrator-level permissions and higher can insert malicious code into webpages. This code would then run every time someone views the page. This issue only affects multi-site installations and websites where the security setting called “”unfiltered_html”” has been switched off.

Detected in:

No API Amazon Affiliate open vulnerable versions: >= * <= 4.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.