CVE-2024-13362
Coupon Affiliates – Affiliate Plugin for WooCommerce
Minimum safe version
7.6.0
Update to 7.6.0 or later to address 22 fixable vulnerabilities
Coupon Affiliates – Affiliate Plugin for WooCommerce <= 7.5.3 - Unauthenticated Stored Cross-Site Scripting
Coupon Affiliates <= 6.8.0 - Missing Authorization
CVE-2025-62884
CVE-2025-54025
CVE-2025-54022
Coupon Affiliates – Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter
CVE-2024-12421
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-29125
Coupon Affiliates for WooCommerce < 4.11.0.2 - Reflected Cross-Site Scripting
Coupon Affiliates for WooCommerce < 4.11.3.4 - Arbitrary Referral Visits Deletion via CSRF
WordPress Coupon Affiliates Plugin < 5.6.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30475
CVE-2023-28992
WooCommerce Affiliate Plugin – Coupon Affiliates <= 4.11.0.1 - Reflected Cross-Site Scripting
WooCommerce Affiliate Plugin – Coupon Affiliates < 4.11.3.4 - Cross-Site Request Forgery
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Coupon Affiliates plugin <= 4.11.0.1 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Coupon Affiliates plugin < 4.16.4.5 - Sensitive Information Disclosure vulnerability
WordPress Coupon Affiliates plugin < 4.16.4.5 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0818