Auto Affiliate Links <= 6.8.8.3 - Missing Authorization
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.8.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.8.8.3
- Fixed in:
- 6.8.9
- Disclosed:
- May 25, 2026
CVE-2026-24592 on NVD →
Auto Affiliate Links <= 6.8.8 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter
high
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(), whe...
- CVSS:
- 7.2
- Affected:
- up to 6.8.8
- Fixed in:
- 6.8.8.1
- Disclosed:
- May 7, 2026
CVE-2026-7330 on NVD →
Auto Affiliate Links [wp-auto-affiliate-links] < 6.2.1.6
unknown
[en] Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.
- Affected:
- up to 6.2.1.6
- Fixed in:
- 6.2.1.6
- Disclosed:
- Dec 13, 2024
CVE-2022-45840 on NVD →
Auto Affiliate Links <= 6.4.6 - Authenticated (Admin+) SQL Injection
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level...
- CVSS:
- 4.9
- Affected:
- up to 6.4.6
- Fixed in:
- 6.4.7
- Disclosed:
- Sep 18, 2024
CVE-2024-9838 on NVD →
Auto Affiliate Links <= 6.4.3.1 - Authenticated (Editor+) SQL Injection
critical
The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level acce...
- CVSS:
- 9.1
- Affected:
- up to 6.4.3.1
- Fixed in:
- 6.4.4
- Disclosed:
- May 6, 2024
CVE-2024-34386 on NVD →
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.4
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.4
- Disclosed:
- May 6, 2024
CVE-2024-34386 on NVD →
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.3.1
unknown
[en] The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to...
- Affected:
- up to 6.4.3.1
- Fixed in:
- 6.4.3.1
- Disclosed:
- Mar 13, 2024
CVE-2024-1843 on NVD →
Auto Affiliate Links <= 6.4.3 - Missing Authorization via aalAddLink
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to posts...
- CVSS:
- 4.3
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.3.1
- Disclosed:
- Mar 11, 2024
CVE-2024-1843 on NVD →
Auto Affiliate Links <= 6.4.2.7 - Cross-Site Request Forgery
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.2.7. This is due to missing or incorrect nonce validation on the wpaal_stats() function. This makes it possible for unauthenticated attackers to reset stats via a forged request granted th...
- CVSS:
- 5.8
- Affected:
- up to 6.4.2.7
- Fixed in:
- 6.4.2.8
- Disclosed:
- Jan 9, 2024
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8
unknown
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.2.7. This is due to missing or incorrect nonce validation on the wpaal_stats() function. This makes it possible for unauthenticated attackers to reset stats via a forged request granted th...
- Affected:
- up to 6.4.2.8
- Fixed in:
- 6.4.2.8
- Disclosed:
- Jan 9, 2024
Auto Affiliate Links <= 6.4.2.5 - Cross-Site Request Forgery
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.2.5. This is due to missing or incorrect nonce validation on several functions such as aal_exclude_terms_actions and aal_exclude_words_actions. This makes it possible for unauthenticated attac...
- CVSS:
- 4.3
- Affected:
- up to 6.4.2.5
- Fixed in:
- 6.4.2.6
- Disclosed:
- Nov 20, 2023
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
unknown
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.4.2.6).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Auto Affiliate Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted ac...
- Affected:
- up to 6.4.2.6
- Fixed in:
- 6.4.2.6
- Disclosed:
- Nov 20, 2023
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
unknown
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.2.5. This is due to missing or incorrect nonce validation on several functions such as aal_exclude_terms_actions and aal_exclude_words_actions. This makes it possible for unauthenticated attac...
- Affected:
- up to 6.4.2.6
- Fixed in:
- 6.4.2.6
- Disclosed:
- Nov 20, 2023
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4.
- Affected:
- up to 6.4.2.5
- Fixed in:
- 6.4.2.5
- Disclosed:
- Nov 13, 2023
CVE-2023-47652 on NVD →
Auto Affiliate Links <= 6.4.2.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.2.4. This is due to missing or incorrect nonce validation on several functions such as aalUpdateExcludePosts(). This makes it possible for unauthenticated attackers to update plugin settings a...
- CVSS:
- 6.1
- Affected:
- up to 6.4.2.4
- Fixed in:
- 6.4.2.5
- Disclosed:
- Nov 7, 2023
CVE-2023-47652 on NVD →
Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.
- Affected:
- up to 6.3.0.1
- Fixed in:
- 6.3.0.1
- Disclosed:
- May 20, 2023
CVE-2023-22689 on NVD →
Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
- Affected:
- up to 6.3.0.3
- Fixed in:
- 6.3.0.3
- Disclosed:
- Mar 13, 2023
CVE-2023-25973 on NVD →
Auto Affiliate Links <= 6.3.0.2 - Cross-Site Request Forgery via aalChangeOptions function
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0.2. This is due to missing or incorrect nonce validation on the 'aalChangeOptions' function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 6.3.0.2
- Fixed in:
- 6.3.0.3
- Disclosed:
- Feb 22, 2023
CVE-2023-25973 on NVD →
Auto Affiliate Links <= 6.2.1.5 - Authenticated (Subscriber+) Plugin Settings Change
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to improper access control via multiple AJAX actions in versions up to, and including, 6.2.1.5. This allows authenticated attackers with subscriber-level permissions or above to modify plugin settings such as adding exclusions for posts and words and to view s...
- CVSS:
- 5.4
- Affected:
- up to 6.2.1.5
- Fixed in:
- 6.2.1.6
- Disclosed:
- Feb 6, 2023
CVE-2022-45840 on NVD →
Auto Affiliate Links <= 6.3 - Cross-Site Request Forgery via aalDeleteLink function
medium
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0.1. This is due to missing or incorrect nonce validation on the aalDeleteLink() function. This makes it possible for unauthenticated attackers to delete links via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 6.3
- Fixed in:
- 6.3.0.1
- Disclosed:
- Feb 2, 2023
CVE-2023-22689 on NVD →
Auto Affiliate Links < 5.0 - SQL Injection
critical
The Auto Affiliate Links plugin for WordPress is vulnerable to multiple SQL Injections via the 'aal_massstring' and 'aalorder' parameters in versions before 5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers...
- CVSS:
- 9.8
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Jul 15, 2015
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
unknown
The Auto Affiliate Links plugin for WordPress is vulnerable to multiple SQL Injections via the 'aal_massstring' and 'aalorder' parameters in versions before 5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers...
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Jul 15, 2015
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
unknown
Because of this vulnerability, authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Jul 15, 2015
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
unknown
The Auto Affiliate Links WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 5.0
- Fixed in:
- 5.0
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
unknown
The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- Affected:
- up to 6.4.2.6
- Fixed in:
- 6.4.2.6
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8
unknown
The plugin is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.2.7. This is due to missing or incorrect nonce validation on the wpaal_stats() function. This makes it possible for unauthenticated attackers to reset stats via a forged request granted they can trick a site administrator i...
- Affected:
- up to 6.4.2.8
- Fixed in:
- 6.4.2.8
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.7
unknown
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.7
CVE-2024-9838 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database