plugin

Thirstyaffiliates Vulnerabilities

10 known security issues reported for the Thirstyaffiliates WordPress plugin. Most recent disclosed Feb 3, 2026.

5 medium

Running Thirstyaffiliates on your site? Check whether your installed version is affected.

Scan your site free

ThirstyAffiliates &#8211; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin [thirstyaffiliates] <= 3.11.9 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue affects ThirstyAffiliates: from n/a through <= 3.11.9.

Affected:
up to 3.11.9
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-25024 on NVD →

ThirstyAffiliates <= 3.11.9 - Cross-Site Request Forgery

medium

The ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.9. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers...

CVSS:
4.3
Affected:
up to 3.11.9
Fixed in:
3.11.10
Disclosed:
Feb 2, 2026

CVE-2026-25024 on NVD →

ThirstyAffiliates <= 3.11.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ThirstyAffiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 3.11.8
Fixed in:
3.11.9
Disclosed:
Dec 15, 2025

CVE-2025-67537 on NVD →

ThirstyAffiliates &#8211; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin [thirstyaffiliates] <= 3.11.8 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Stored XSS.This issue affects ThirstyAffiliates: from n/a through <= 3.11.8.

Affected:
up to 3.11.8
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67537 on NVD →

ThirstyAffiliates &#8211; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin [thirstyaffiliates] < 3.10.5

unknown

[en] The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 25, 2022

CVE-2022-0398 on NVD →

ThirstyAffiliates &#8211; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin [thirstyaffiliates] < 3.10.5

unknown

[en] The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a l...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 25, 2022

CVE-2022-0634 on NVD →

ThirstyAffiliates Affiliate Link Manager <= 3.10.4 - Authorization Bypass and Cross-Site Request Forgery

medium

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks CSRF checks, allowing an att...

CVSS:
5.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 10, 2022

CVE-2022-0634 on NVD →

ThirstyAffiliates Affiliate Link Manager <= 3.10.4 - Subscriber+ Arbitrary Affiliate Links Creation

medium

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site Request Forgery checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an...

CVSS:
5.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 10, 2022

CVE-2022-0398 on NVD →

ThirstyAffiliates &#8211; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin [thirstyaffiliates] < 3.9.3

unknown

[en] Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
Mar 18, 2021

CVE-2021-24127 on NVD →

ThirstyAffiliates Affiliate Link Manager <= 3.9.2 - Stored Cross-Site Scripting

medium

Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.

CVSS:
5.4
Affected:
up to 3.9.2
Fixed in:
3.9.3
Disclosed:
May 22, 2020

CVE-2021-24127 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database