The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Amazon_affiliate_wordpress_plugin | Getaawp | * | 3.12.3 (excluding) |