Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpaffiliatemanager

First CVE: Sep 3, 2019Active for: 7 yearsTotal CVEs: 9

WPAffiliateManager is a narrowly scoped WordPress plugin focused on affiliate-program management that occupies a niche within the broader WordPress ecosystem. Its vulnerabilities cluster around web-application input and output handling—including cross-site request forgery, cross-site scripting, SQL injection, and CSV formula injection—alongside information-disclosure weaknesses characteristic of plugins managing sensitive affiliate data and transaction records. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpaffiliatemanager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2019
6 years ago
Most Recent CVE
Feb 5, 2024
903 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25078MEDIUM
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticate
Jan 24, 20226.131NOYES
CVE-2019-15868HIGH
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
Sep 3, 20198.828NONO
CVE-2022-2798HIGH
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection a
Sep 16, 20228.026NONO
CVE-2023-52130HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.
Jan 5, 20248.824NONO
CVE-2023-28986HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager plugin <= 2.9.20 versions.
Jul 10, 20238.824NONO
CVE-2021-24844HIGH
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection
Nov 8, 20217.224NONO
CVE-2022-2799MEDIUM
The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting atta
Sep 16, 20224.819NONO
CVE-2023-52148MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.
Jan 5, 20245.317NONO
CVE-2024-0859MEDIUM
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce vali
Feb 5, 20244.315NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
56%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (22.2%)
Unknown0 (0.0%)
Required7 (77.8%)
Privileges Required
Low1 (11.1%)
High2 (22.2%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpaffiliatemanager.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpaffiliatemanager — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpaffiliatemanager's Products

View all 4 CNAs →

Top CWEs