Affiliates Manager [wp-affiliate-platform] < 6.5.2
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack
- Affected:
- up to 6.5.2
- Fixed in:
- 6.5.2
- Disclosed:
- Jul 29, 2024
CVE-2024-5285 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5281 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5287 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5286 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5283 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5282 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5284 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.5.1
unknown
[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jul 13, 2024
CVE-2024-5280 on NVD →
WP Affiliate Platform <= 6.5.1 - Cross-Site Request Forgery to Afilliate Deletion
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.1. This is due to missing or incorrect nonce validation on the affiliate 'delete' functionality. This makes it possible for unauthenticated attackers to delete affiliates via a forged req...
- CVSS:
- 5.4
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.2
- Disclosed:
- Jul 8, 2024
CVE-2024-5285 on NVD →
WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Affiliate Editing
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editaff' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5281 on NVD →
WP Affiliate Platform <= 6.5.0 - Cross-Site Request Forgery to Cross-Site Scripting
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.0. This is due to missing or incorrect nonce validation on the 'info_update' functionality. This makes it possible for unauthenticated attackers to update settings and inject malicious we...
- CVSS:
- 6.1
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5280 on NVD →
WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Lead Editing
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wp_aff_referrer' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.1
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5283 on NVD →
WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Registration Form
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'afirstname' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5282 on NVD →
WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Banner Editing
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5286 on NVD →
WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the wp_aff_platform_settings page. This makes it possible for unauthenticated attackers to update settings and inject malicious web...
- CVSS:
- 6.1
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5284 on NVD →
WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Profile Update
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the profile update functionality. This makes it possible for unauthenticated attackers to update profiles via a forged request grant...
- CVSS:
- 5.4
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.1
- Disclosed:
- Jun 22, 2024
CVE-2024-5287 on NVD →
Affiliates Manager [wp-affiliate-platform] < 2.7.8
unknown
Update WordPress Affiliates Manager to the latest available version (at least 2.7.8).
Till Oberbeckmann & Jan Kahmen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Affiliate Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Sep 14, 2023
Affiliates Manager [wp-affiliate-platform] < 6.4.0
unknown
[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 29, 2022
CVE-2022-3897 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.4.0
unknown
[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 29, 2022
CVE-2022-3896 on NVD →
Affiliates Manager [wp-affiliate-platform] < 6.4.0
unknown
[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliat...
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 29, 2022
CVE-2022-3898 on NVD →
WP Affiliate Platform <= 6.3.9 - Cross-Site Request Forgery
high
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliate rec...
- CVSS:
- 8.8
- Affected:
- up to 6.3.9
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 8, 2022
CVE-2022-3898 on NVD →
WP Affiliate Platform <= 6.3.9 - Reflected Cross-Site Scripting
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 6.3.9
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 8, 2022
CVE-2022-3896 on NVD →
WP Affiliate Platform <= 6.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...
- CVSS:
- 5.5
- Affected:
- up to 6.3.9
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 8, 2022
CVE-2022-3897 on NVD →
Affiliates Manager [wp-affiliate-platform] < 2.7.8
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by Till Oberbeckmann and Jan Kahmen in WordPress Affiliates Manager (versions <= 2.7.7).
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
- Disclosed:
- Sep 14, 2020
Affiliates Manager [wp-affiliate-platform] < 1.1
unknown
Update the plugin.
Felipe Andrian Peixoto discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Affiliate Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Aug 1, 2014
Affiliates Manager [wp-affiliate-platform] < 1.1
unknown
This plugin is prone to a login.php msg parameter XSS.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Aug 1, 2014
WP Affiliate Platform <= 6.3.8 - Reflected Cross-Site Scripting
medium
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in the 'login.php' file due to insufficient input sanitization and output escaping. This affects versions up to and including 6.3.8. This makes it possible for unauthenticated attackers to inject arbit...
- CVSS:
- 6.1
- Affected:
- up to 6.3.8
- Fixed in:
- 6.3.9
- Disclosed:
- May 1, 2014
Affiliates Manager [wp-affiliate-platform] < 6.3.9
unknown
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in the 'login.php' file due to insufficient input sanitization and output escaping. This affects versions up to and including 6.3.8. This makes it possible for unauthenticated attackers to inject arbit...
- Affected:
- up to 6.3.9
- Fixed in:
- 6.3.9
- Disclosed:
- May 1, 2014
Affiliates Manager [wp-affiliate-platform] < 1.1
unknown
The plugin does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database