plugin

Wp Affiliate Platform Vulnerabilities

29 known security issues reported for the Wp Affiliate Platform WordPress plugin. Most recent disclosed Jul 29, 2024.

1 high 11 medium

Running Wp Affiliate Platform on your site? Check whether your installed version is affected.

Scan your site free

Affiliates Manager [wp-affiliate-platform] < 6.5.2

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

Affected:
up to 6.5.2
Fixed in:
6.5.2
Disclosed:
Jul 29, 2024

CVE-2024-5285 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5281 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5287 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5286 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5283 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5282 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5284 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.5.1

unknown

[en] The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jul 13, 2024

CVE-2024-5280 on NVD →

WP Affiliate Platform <= 6.5.1 - Cross-Site Request Forgery to Afilliate Deletion

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.1. This is due to missing or incorrect nonce validation on the affiliate 'delete' functionality. This makes it possible for unauthenticated attackers to delete affiliates via a forged req...

CVSS:
5.4
Affected:
up to 6.5.1
Fixed in:
6.5.2
Disclosed:
Jul 8, 2024

CVE-2024-5285 on NVD →

WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Affiliate Editing

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editaff' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5281 on NVD →

WP Affiliate Platform <= 6.5.0 - Cross-Site Request Forgery to Cross-Site Scripting

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.0. This is due to missing or incorrect nonce validation on the 'info_update' functionality. This makes it possible for unauthenticated attackers to update settings and inject malicious we...

CVSS:
6.1
Affected:
up to 6.5.0
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5280 on NVD →

WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Lead Editing

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wp_aff_referrer' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
6.1
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5283 on NVD →

WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Registration Form

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'afirstname' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5282 on NVD →

WP Affiliate Platform < 6.5.1 - Reflected Cross-Site Scripting via Banner Editing

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5286 on NVD →

WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the wp_aff_platform_settings page. This makes it possible for unauthenticated attackers to update settings and inject malicious web...

CVSS:
6.1
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5284 on NVD →

WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Profile Update

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the profile update functionality. This makes it possible for unauthenticated attackers to update profiles via a forged request grant...

CVSS:
5.4
Affected:
up to 6.5.1
Fixed in:
6.5.1
Disclosed:
Jun 22, 2024

CVE-2024-5287 on NVD →

Affiliates Manager [wp-affiliate-platform] < 2.7.8

unknown

Update WordPress Affiliates Manager to the latest available version (at least 2.7.8). Till Oberbeckmann & Jan Kahmen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Affiliate Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisem...

Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
Sep 14, 2023

Affiliates Manager [wp-affiliate-platform] < 6.4.0

unknown

[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 29, 2022

CVE-2022-3897 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.4.0

unknown

[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 29, 2022

CVE-2022-3896 on NVD →

Affiliates Manager [wp-affiliate-platform] < 6.4.0

unknown

[en] The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliat...

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 29, 2022

CVE-2022-3898 on NVD →

WP Affiliate Platform <= 6.3.9 - Cross-Site Request Forgery

high

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for unauthenticated attackers to delete affiliate rec...

CVSS:
8.8
Affected:
up to 6.3.9
Fixed in:
6.4.0
Disclosed:
Nov 8, 2022

CVE-2022-3898 on NVD →

WP Affiliate Platform <= 6.3.9 - Reflected Cross-Site Scripting

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 6.3.9
Fixed in:
6.4.0
Disclosed:
Nov 8, 2022

CVE-2022-3896 on NVD →

WP Affiliate Platform <= 6.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...

CVSS:
5.5
Affected:
up to 6.3.9
Fixed in:
6.4.0
Disclosed:
Nov 8, 2022

CVE-2022-3897 on NVD →

Affiliates Manager [wp-affiliate-platform] < 2.7.8

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by Till Oberbeckmann and Jan Kahmen in WordPress Affiliates Manager (versions <= 2.7.7).

Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
Sep 14, 2020

Affiliates Manager [wp-affiliate-platform] < 1.1

unknown

Update the plugin. Felipe Andrian Peixoto discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Affiliate Manager Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Affiliates Manager [wp-affiliate-platform] < 1.1

unknown

This plugin is prone to a login.php msg parameter XSS. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

WP Affiliate Platform <= 6.3.8 - Reflected Cross-Site Scripting

medium

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in the 'login.php' file due to insufficient input sanitization and output escaping. This affects versions up to and including 6.3.8. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
6.1
Affected:
up to 6.3.8
Fixed in:
6.3.9
Disclosed:
May 1, 2014

Affiliates Manager [wp-affiliate-platform] < 6.3.9

unknown

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in the 'login.php' file due to insufficient input sanitization and output escaping. This affects versions up to and including 6.3.8. This makes it possible for unauthenticated attackers to inject arbit...

Affected:
up to 6.3.9
Fixed in:
6.3.9
Disclosed:
May 1, 2014

Affiliates Manager [wp-affiliate-platform] < 1.1

unknown

The plugin does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

Affected:
up to 1.1
Fixed in:
1.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database