N/A
2026-05-06< 1.2.7
Affiliate Program Suite — SliceWP Affiliates <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting
Minimum safe version
1.2.8
Update to 1.2.8 or later to address 9 fixable vulnerabilities
Affiliate Program Suite — SliceWP Affiliates <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-6672
CVE-2024-12454
CVE-2024-47388
WordPress SliceWP Plugin <= 1.1.20 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-34413
SliceWP < 1.0.46 - Reflected Cross-Site Scripting (XSS)
WordPress Affiliates Plugin — SliceWP Affiliates <= 1.0.45 - Cross-Site Scripting
WordPress SliceWP plugin <= 1.0.45 - Reflected Cross-Site Scripting (XSS) vulnerability