
CVE-2026-7330 The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input san… https://www.cve.org/CVERecord?id=CVE-2026-7330
Post summary
The CVE-2026-7330 disclosure highlights a stored XSS flaw in the Auto Affiliate Links WordPress plugin (v6.8.8 and earlier) caused by insufficient input sanitization; no PoC, exploit, patch, or active exploitation details are provided.


