Freemius SDK <= 2.4.2 - Missing Authorization Checks
WP Affiliate Disclosure
Minimum safe version
1.2.8
Update to 1.2.8 or later to address 10 fixable vulnerabilities
WordPress WP Affiliate Disclosure Plugin <= 1.2.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47232
WordPress WP Affiliate Disclosure Plugin < 1.2.6 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress WP Affiliate Disclosure plugin <=1.1.3 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress WP Affiliate Disclosure plugin < 1.2.3 - Sensitive Information Disclosure vulnerability
WordPress WP Affiliate Disclosure plugin < 1.2.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability