AffiliateWP is a WordPress plugin that provides affiliate-marketing functionality for WordPress-based e-commerce and content platforms. The vendor's vulnerability profile reflects its role as a plugin component in a widely deployed web platform, with disclosures concentrated in the single product line. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Affiliatewp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57809HIGH Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | Jul 23, 2026 | 7.1 | 29 | NO | NO |
CVE-2025-8877HIGH The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and including, 2.28.2 due to insufficie | Sep 30, 2025 | 7.5 | 26 | NO | NO |
CVE-2023-4600MEDIUM The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'affwp_activate_addons_page_plugin' function called via an | Aug 30, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Affiliatewp.
Media articles that mention a CVE ID that affects a product developed by Affiliatewp — matched by CVE ID, not by vendor name.