WPAffiliateManager is a narrowly scoped WordPress plugin focused on affiliate-program management that occupies a niche within the broader WordPress ecosystem. Its vulnerabilities cluster around web-application input and output handling—including cross-site request forgery, cross-site scripting, SQL injection, and CSV formula injection—alongside information-disclosure weaknesses characteristic of plugins managing sensitive affiliate data and transaction records. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpaffiliatemanager over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25078MEDIUM The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticate | Jan 24, 2022 | 6.1 | 31 | NO | YES |
CVE-2019-15868HIGH The affiliates-manager plugin before 2.6.6 for WordPress has CSRF. | Sep 3, 2019 | 8.8 | 28 | NO | NO |
CVE-2022-2798HIGH The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection a | Sep 16, 2022 | 8.0 | 26 | NO | NO |
CVE-2023-52130HIGH Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31. | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-28986HIGH Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager plugin <= 2.9.20 versions. | Jul 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24844HIGH The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection | Nov 8, 2021 | 7.2 | 24 | NO | NO |
CVE-2022-2799MEDIUM The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting atta | Sep 16, 2022 | 4.8 | 19 | NO | NO |
CVE-2023-52148MEDIUM Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2. | Jan 5, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-0859MEDIUM The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce vali | Feb 5, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpaffiliatemanager.
Media articles that mention a CVE ID that affects a product developed by Wpaffiliatemanager — matched by CVE ID, not by vendor name.