plugin

Affiliates Manager Vulnerabilities

16 known security issues reported for the Affiliates Manager WordPress plugin. Most recent disclosed Aug 18, 2026.

1 critical 6 high 9 medium

Running Affiliates Manager on your site? Check whether your installed version is affected.

Scan your site free

Affiliates Manager <= 2.9.53 - Unauthenticated SQL Injection

high

The Affiliates Manager plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.9.53. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additi...

CVSS:
7.5
Affected:
up to 2.9.53
Fixed in:
2.9.54
Disclosed:
Aug 18, 2026

CVE-2026-73355 on NVD →

Affiliates Manager <= 2.9.53 - Unauthenticated Stored Cross-Site Scripting

high

The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.53. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 2.9.53
Fixed in:
2.9.54
Disclosed:
Aug 18, 2026

CVE-2026-73358 on NVD →

Affiliates Manager <= 2.9.49 - Missing Authorization

medium

The Affiliates Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.49. This makes it possible for authenticated attackers, with affiliate-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.9.49
Fixed in:
2.9.50
Disclosed:
Jun 26, 2026

CVE-2026-57654 on NVD →

Affiliates Manager <= 2.9.50 - Unauthenticated Information Exposure

medium

The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.50. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.9.50
Fixed in:
2.9.51
Disclosed:
Jun 8, 2026

CVE-2026-52692 on NVD →

Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery

medium

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on the process_bulk_action function in ListAffiliatesTable.php. This makes it possible for unauthenticated attackers to delete affili...

CVSS:
4.3
Affected:
up to 2.9.34
Fixed in:
2.9.35
Disclosed:
Jan 30, 2024

CVE-2024-0859 on NVD →

Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions

medium

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.31. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to approve, decline, and block affiliate applications an...

CVSS:
6.5
Affected:
up to 2.9.31
Fixed in:
2.9.32
Disclosed:
Dec 28, 2023

CVE-2023-52130 on NVD →

Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File

medium

The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.30 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and debug information.

CVSS:
5.3
Affected:
up to 2.9.30
Fixed in:
2.9.31
Disclosed:
Dec 28, 2023

CVE-2023-52148 on NVD →

Affiliates Manager <= 2.9.20 - Cross-Site Request Forgery via process_bulk_action()

medium

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.20. This is due to missing nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to perform bulk modifications of commissions and clicks vi...

CVSS:
4.3
Affected:
up to 2.9.20
Fixed in:
2.9.21
Disclosed:
Mar 29, 2023

CVE-2023-28986 on NVD →

Affiliates Manager <= 2.9.13 - CSV Injection

critical

The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. This allows [authentication level?] attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vuln...

CVSS:
9
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Aug 16, 2022

CVE-2022-2798 on NVD →

Affiliates Manager <= 2.9.13 - Cross-Site Request Forgery

high

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.13. This is due to missing or incorrect nonce validation on the process_individual_action function. This makes it possible for unauthenticated attackers to delete affiliates and commissions, via...

CVSS:
8.8
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Aug 16, 2022

Affiliates Manager <= 2.9.13 - Reflected Cross-Site Scripting

medium

The Affiliates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘newurl’ parameter in versions up to, and including, 1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Aug 16, 2022

Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

CVSS:
5.5
Affected:
up to 2.9.13
Fixed in:
2.9.14
Disclosed:
Aug 16, 2022

CVE-2022-2799 on NVD →

Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting

high

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVSS:
7.2
Affected:
up to 2.8.9
Fixed in:
2.9.0
Disclosed:
Dec 24, 2021

CVE-2021-25078 on NVD →

Affiliate Manager <= 2.8.6 - Admin+ SQL injection

high

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

CVSS:
7.2
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Oct 11, 2021

CVE-2021-24844 on NVD →

Affiliates Manager <= 2.7.7 - Cross-Site Scripting

medium

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
Sep 11, 2020

Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery

high

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This makes it possible for unauthenticated attackers to perform unspecified modifications to the plugin settings granted they can trick a site administrator into performing an action such as clicking on a l...

CVSS:
8.8
Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
May 26, 2019

CVE-2019-15868 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database