Flamescorpion's vulnerability footprint concentrates in its Auto Affiliate Links product, with durable weaknesses centered on web application input handling and access control, including cross-site request forgery, SQL injection, and missing authorization checks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flamescorpion over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22689HIGH Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions. | May 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-25973HIGH Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. | Mar 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-47652MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4. | Nov 13, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-9838MEDIUM The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | May 15, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-1843MEDIUM The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, | Mar 13, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flamescorpion.
Media articles that mention a CVE ID that affects a product developed by Flamescorpion — matched by CVE ID, not by vendor name.