CVE-2026-19573
Last modified
CVE-2026-19573 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| worschtebrot | Affiliate Super Assistent | <= 1.10.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19573?
How severe is CVE-2026-19573?
How do I fix CVE-2026-19573?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19561Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-19562Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-19563Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-19565Apache::AppSamurai::Util versions through 1.01 for Perl gene…3.7
- CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory ex…7.5
- CVE-2026-19568A maliciously crafted SVG file, when parsed through Autodesk…7.8
- CVE-2026-19579Snipe-IT before 8.6.0 contains an authorization bypass (inse…5.4
- CVE-2026-1958Use of hard-coded credentials in Klinika XP and KlinikaXP In…8.7
- CVE-2026-19582Rejected reason: Red Hat Product Security has come to the co…
- CVE-2026-19583Velociraptor allows some sensitive artifacts to be gated by …9.9
- CVE-2026-19584Velociraptor allows for the creation of notebook backups in …7.7
- CVE-2026-19586A pre-authentication OS command injection vulnerability has …9.8
Are you affected by CVE-2026-19573?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
