Mojofywp maintains a WordPress affiliate disclosure plugin with a narrow but specialized role in affiliate content management and transparency workflows. The observed vulnerability profile centers on cross-site scripting weaknesses in web page generation, a class endemic to user-input handling in plugin-based content systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mojofywp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47232MEDIUM Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6. | Dec 21, 2025 | 4.3 | 18 | NO | NO |
CVE-2023-52178MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP WP Affiliate Disclosure allows Stored XSS.This issue affects WP Affil | Jan 5, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mojofywp.
Media articles that mention a CVE ID that affects a product developed by Mojofywp — matched by CVE ID, not by vendor name.