Affiliates Manager <= 2.9.53 - Unauthenticated SQL Injection
high
The Affiliates Manager plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.9.53. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additi...
- CVSS:
- 7.5
- Affected:
- up to 2.9.53
- Fixed in:
- 2.9.54
- Disclosed:
- Aug 18, 2026
CVE-2026-73355 on NVD →
Affiliates Manager <= 2.9.53 - Unauthenticated Stored Cross-Site Scripting
high
The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.53. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 2.9.53
- Fixed in:
- 2.9.54
- Disclosed:
- Aug 18, 2026
CVE-2026-73358 on NVD →
Affiliates Manager <= 2.9.49 - Missing Authorization
medium
The Affiliates Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.49. This makes it possible for authenticated attackers, with affiliate-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.9.49
- Fixed in:
- 2.9.50
- Disclosed:
- Jun 26, 2026
CVE-2026-57654 on NVD →
Affiliates Manager <= 2.9.50 - Unauthenticated Information Exposure
medium
The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.50. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.9.50
- Fixed in:
- 2.9.51
- Disclosed:
- Jun 8, 2026
CVE-2026-52692 on NVD →
Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery
medium
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on the process_bulk_action function in ListAffiliatesTable.php. This makes it possible for unauthenticated attackers to delete affili...
- CVSS:
- 4.3
- Affected:
- up to 2.9.34
- Fixed in:
- 2.9.35
- Disclosed:
- Jan 30, 2024
CVE-2024-0859 on NVD →
Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions
medium
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.31. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to approve, decline, and block affiliate applications an...
- CVSS:
- 6.5
- Affected:
- up to 2.9.31
- Fixed in:
- 2.9.32
- Disclosed:
- Dec 28, 2023
CVE-2023-52130 on NVD →
Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File
medium
The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.30 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and debug information.
- CVSS:
- 5.3
- Affected:
- up to 2.9.30
- Fixed in:
- 2.9.31
- Disclosed:
- Dec 28, 2023
CVE-2023-52148 on NVD →
Affiliates Manager <= 2.9.20 - Cross-Site Request Forgery via process_bulk_action()
medium
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.20. This is due to missing nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to perform bulk modifications of commissions and clicks vi...
- CVSS:
- 4.3
- Affected:
- up to 2.9.20
- Fixed in:
- 2.9.21
- Disclosed:
- Mar 29, 2023
CVE-2023-28986 on NVD →
Affiliates Manager <= 2.9.13 - CSV Injection
critical
The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. This allows [authentication level?] attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vuln...
- CVSS:
- 9
- Affected:
- up to 2.9.13
- Fixed in:
- 2.9.14
- Disclosed:
- Aug 16, 2022
CVE-2022-2798 on NVD →
Affiliates Manager <= 2.9.13 - Cross-Site Request Forgery
high
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.13. This is due to missing or incorrect nonce validation on the process_individual_action function. This makes it possible for unauthenticated attackers to delete affiliates and commissions, via...
- CVSS:
- 8.8
- Affected:
- up to 2.9.13
- Fixed in:
- 2.9.14
- Disclosed:
- Aug 16, 2022
Affiliates Manager <= 2.9.13 - Reflected Cross-Site Scripting
medium
The Affiliates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘newurl’ parameter in versions up to, and including, 1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 2.9.13
- Fixed in:
- 2.9.14
- Disclosed:
- Aug 16, 2022
Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- CVSS:
- 5.5
- Affected:
- up to 2.9.13
- Fixed in:
- 2.9.14
- Disclosed:
- Aug 16, 2022
CVE-2022-2799 on NVD →
Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting
high
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
- CVSS:
- 7.2
- Affected:
- up to 2.8.9
- Fixed in:
- 2.9.0
- Disclosed:
- Dec 24, 2021
CVE-2021-25078 on NVD →
Affiliate Manager <= 2.8.6 - Admin+ SQL injection
high
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue
- CVSS:
- 7.2
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Oct 11, 2021
CVE-2021-24844 on NVD →
Affiliates Manager <= 2.7.7 - Cross-Site Scripting
medium
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Sep 11, 2020
Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery
high
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This makes it possible for unauthenticated attackers to perform unspecified modifications to the plugin settings granted they can trick a site administrator into performing an action such as clicking on a l...
- CVSS:
- 8.8
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.6
- Disclosed:
- May 26, 2019
CVE-2019-15868 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database