ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] <= 3.11.9 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue affects ThirstyAffiliates: from n/a through <= 3.11.9.
- Affected:
- up to 3.11.9
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-25024 on NVD →
ThirstyAffiliates <= 3.11.9 - Cross-Site Request Forgery
medium
The ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers...
- CVSS:
- 4.3
- Affected:
- up to 3.11.9
- Fixed in:
- 3.11.10
- Disclosed:
- Feb 2, 2026
CVE-2026-25024 on NVD →
ThirstyAffiliates <= 3.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ThirstyAffiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 3.11.8
- Fixed in:
- 3.11.9
- Disclosed:
- Dec 15, 2025
CVE-2025-67537 on NVD →
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] <= 3.11.8 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Stored XSS.This issue affects ThirstyAffiliates: from n/a through <= 3.11.8.
- Affected:
- up to 3.11.8
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67537 on NVD →
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5
unknown
[en] The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 25, 2022
CVE-2022-0398 on NVD →
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5
unknown
[en] The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a l...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 25, 2022
CVE-2022-0634 on NVD →
ThirstyAffiliates Affiliate Link Manager <= 3.10.4 - Authorization Bypass and Cross-Site Request Forgery
medium
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks CSRF checks, allowing an att...
- CVSS:
- 5.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 10, 2022
CVE-2022-0634 on NVD →
ThirstyAffiliates Affiliate Link Manager <= 3.10.4 - Subscriber+ Arbitrary Affiliate Links Creation
medium
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site Request Forgery checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an...
- CVSS:
- 5.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 10, 2022
CVE-2022-0398 on NVD →
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.9.3
unknown
[en] Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Mar 18, 2021
CVE-2021-24127 on NVD →
ThirstyAffiliates Affiliate Link Manager <= 3.9.2 - Stored Cross-Site Scripting
medium
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.
- CVSS:
- 5.4
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.3
- Disclosed:
- May 22, 2020
CVE-2021-24127 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database