CVE-2024-0859
Affiliates Manager
Minimum safe version
2.9.35
Update to 2.9.35 or later to address 19 fixable vulnerabilities
WordPress Affiliates Manager Plugin <= 2.9.31 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data Exposure
Affiliates Manager < 2.9.14 - Reflected Cross-Site Scripting
Affiliates Manager < 2.9.14 - Arbitrary Affiliates & Creatives Deletion via CSRF
CVE-2023-28986
Affiliates Manager <= 2.7.7 - Cross-Site Scripting
Affiliates Manager <= 2.9.13 - Reflected Cross-Site Scripting
Affiliates Manager <= 2.9.13 - Cross-Site Request Forgery
Affiliate Manager < 2.7.8 - Unauthenticated Stored Cross-Site Scripting (XSS)
CVE-2022-2798
CVE-2022-2799
WordPress Affiliates Manager Plugin <= 2.9.13 - Arbitrary Affiliates & Creatives Deletion via CSRF vulnerability
WordPress Affiliates Manager Plugin <= 2.9.13 - Reflected Cross-Site Scripting vulnerability
WordPress Affiliates Manager plugin <= 2.6.5 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Affiliates Manager plugin <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2019-15868
CVE-2021-24844
CVE-2021-25078