What this page helps you verify fast
This hub clusters tracked records for Affiliates Manager so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Affiliates Manager (`affiliates-manager`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2024-0859, CVE-2023-52148 and CVE-2023-52130, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 2.9.13. Fixed version: 2.9.14.
Affected range: Versions before 2.6.6. Fixed version: 2.6.6.
Affected range: Versions up to 2.8.9. Fixed version: 2.9.0.
Affected range: Versions up to 2.8.6. Fixed version: 2.8.7.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2022-2798
Affiliates Manager <= 2.9.13 - CSV Injection
|
Vulnerability | Versions up to 2.9.13 | 2.9.14 | CVSS 9.0 |
|
CVE-2019-15868
Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery
|
Cross-Site Request Forgery | Versions before 2.6.6 | 2.6.6 | CVSS 8.8 |
|
CVE-2021-25078
Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting
|
Stored Cross-Site Scripting | Versions up to 2.8.9 | 2.9.0 | CVSS 7.2 |
|
CVE-2021-24844
Affiliate Manager <= 2.8.6 - Admin+ SQL injection
|
SQL Injection | Versions up to 2.8.6 | 2.8.7 | CVSS 7.2 |
|
CVE-2023-52130
Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions
|
Cross-Site Request Forgery | Versions up to 2.9.31 | 2.9.32 | CVSS 6.5 |
|
CVE-2022-2799
Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scri...
|
Stored Cross-Site Scripting | Versions up to 2.9.13 | 2.9.14 | CVSS 5.5 |
|
CVE-2023-52148
Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File
|
Sensitive Information Exposure | Versions up to 2.9.30 | 2.9.31 | CVSS 5.3 |
|
CVE-2024-0859
Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery
|
Cross-Site Request Forgery | Versions up to 2.9.34 | 2.9.35 | CVSS 4.3 |
Affiliates Manager <= 2.9.13 - CSV Injection
Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery
Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting
Affiliate Manager <= 2.8.6 - Admin+ SQL injection
Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions
Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scripting
Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File
Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery
This hub clusters tracked records for Affiliates Manager so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on...
The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.30 via the plugin's log files. This makes it possible fo...
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.31. This is due to missing or incorrect nonce validation on mult...
Sorted by latest disclosure date so newly published issues surface first.
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on the process_bulk_action function in ListAffiliatesTable.php. This makes it possible for un...
The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.30 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and d...
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.31. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to approve, decl...
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.20. This is due to missing nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to perform bulk mo...
The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. This allows [authentication level?] attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...
The Affiliates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘newurl’ parameter in versions up to, and including, 1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.13. This is due to missing or incorrect nonce validation on the process_individual_action function. This makes it possible for unauthenticated attackers t...
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's br...
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This makes it possible for unauthenticated attackers to perform unspecified modifications to the plugin settings granted they can trick a site administrator into perf...