Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
4 attempts · first 2026-07-10T14:30:01.097818Z · last 2026-07-21T20:45:02.379366Z
Not listed in CISA KEV (local)
Types: cisa_kev
4 attempts · first 2026-07-10T14:30:01.089988Z · last 2026-07-21T20:45:02.357799Z
EPSS=0.00266
Types: epss
4 attempts · first 2026-07-10T14:30:01.100671Z · last 2026-07-21T20:45:02.387967Z
The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.