Plugin Vulnerability Hub
Plugin 12 known issues Latest disclosed Jan 30, 2024

Affiliates Manager Vulnerabilities

Review known vulnerability records for the WordPress plugin Affiliates Manager (`affiliates-manager`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2024-0859, CVE-2023-52148 and CVE-2023-52130, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
12
High or Critical
5
Patch Coverage
100%
Last Updated
Jul 29, 2024
Related Security Guides

Use these guides while reviewing Affiliates Manager fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Affiliates Manager remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
10
1. Match the Package
Confirm the installed WordPress plugin slug is affiliates-manager before acting on any CVE from this cluster.
2. Sort by Severity
Start with 5 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
12 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Affiliates Manager CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
9
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2022-2798
Affiliates Manager <= 2.9.13 - CSV Injection
Vulnerability Versions up to 2.9.13 2.9.14 CVSS 9.0
CVE-2019-15868
Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 2.6.6 2.6.6 CVSS 8.8
CVE-2021-25078
Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions up to 2.8.9 2.9.0 CVSS 7.2
CVE-2021-24844
Affiliate Manager <= 2.8.6 - Admin+ SQL injection
SQL Injection Versions up to 2.8.6 2.8.7 CVSS 7.2
CVE-2023-52130
Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions
Cross-Site Request Forgery Versions up to 2.9.31 2.9.32 CVSS 6.5
CVE-2022-2799
Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scri...
Stored Cross-Site Scripting Versions up to 2.9.13 2.9.14 CVSS 5.5
CVE-2023-52148
Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File
Sensitive Information Exposure Versions up to 2.9.30 2.9.31 CVSS 5.3
CVE-2024-0859
Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions up to 2.9.34 2.9.35 CVSS 4.3
Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Affiliates Manager so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
12 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 4 high severity findings.
Recent CVEs
CVE-2024-0859, CVE-2023-52148 and CVE-2023-52130
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Affiliates Manager

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2024-0859
CVE-2024-0859: Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing or incorrect nonce validation on the process_bulk_action function in ListAffiliatesTable.php. This makes it possible for un...

Published
Jan 30, 2024
Patched Release
2.9.35
Affected Versions
Versions up to 2.9.34
Next Step
Update to 2.9.35 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-52148
CVE-2023-52148: Affiliates Manager <= 2.9.30 - Sensitive Information Exposure via Log File

The Affiliates Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.30 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and d...

Published
Dec 28, 2023
Patched Release
2.9.31
Affected Versions
Versions up to 2.9.30
Next Step
Update to 2.9.31 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-52130
CVE-2023-52130: Affiliates Manager <= 2.9.31 - Cross-Site Request Forgery via multiple AJAX actions

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.31. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to approve, decl...

Published
Dec 28, 2023
Patched Release
2.9.32
Affected Versions
Versions up to 2.9.31
Next Step
Update to 2.9.32 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-28986
CVE-2023-28986: Affiliates Manager <= 2.9.20 - Cross-Site Request Forgery via process_bulk_action()

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.20. This is due to missing nonce validation on the process_bulk_action() function. This makes it possible for unauthenticated attackers to perform bulk mo...

Published
Mar 29, 2023
Patched Release
2.9.21
Affected Versions
Versions up to 2.9.20
Next Step
Update to 2.9.21 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-2799
CVE-2022-2799: Affiliates Manager <= 2.9.13 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Affiliates Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published
Aug 16, 2022
Patched Release
2.9.14
Affected Versions
Versions up to 2.9.13
Next Step
Update to 2.9.14 or newer if supported.
Plugin Critical Patched: Yes CVE-2022-2798
CVE-2022-2798: Affiliates Manager <= 2.9.13 - CSV Injection

The Affiliates Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.13. This allows [authentication level?] attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded...

Published
Aug 16, 2022
Patched Release
2.9.14
Affected Versions
Versions up to 2.9.13
Next Step
Update to 2.9.14 or newer if supported.
Plugin Medium Patched: Yes
Affiliates Manager <= 2.9.13 - Reflected Cross-Site Scripting

The Affiliates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘newurl’ parameter in versions up to, and including, 1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Published
Aug 16, 2022
Patched Release
2.9.14
Affected Versions
Versions up to 2.9.13
Next Step
Update to 2.9.14 or newer if supported.
Plugin High Patched: Yes
Affiliates Manager <= 2.9.13 - Cross-Site Request Forgery

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.13. This is due to missing or incorrect nonce validation on the process_individual_action function. This makes it possible for unauthenticated attackers t...

Published
Aug 16, 2022
Patched Release
2.9.14
Affected Versions
Versions up to 2.9.13
Next Step
Update to 2.9.14 or newer if supported.
Plugin High Patched: Yes CVE-2021-25078
CVE-2021-25078: Affiliates Manager <= 2.8.9 - Unauthenticated Stored Cross-Site Scripting

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

Published
Dec 24, 2021
Patched Release
2.9.0
Affected Versions
Versions up to 2.8.9
Next Step
Update to 2.9.0 or newer if supported.
Plugin High Patched: Yes CVE-2021-24844
CVE-2021-24844: Affiliate Manager <= 2.8.6 - Admin+ SQL injection

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

Published
Oct 11, 2021
Patched Release
2.8.7
Affected Versions
Versions up to 2.8.6
Next Step
Update to 2.8.7 or newer if supported.
Plugin Medium Patched: Yes
Affiliates Manager <= 2.7.7 - Cross-Site Scripting

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's br...

Published
Sep 11, 2020
Patched Release
2.7.8
Affected Versions
Versions before 2.7.8
Next Step
Update to 2.7.8 or newer if supported.
Plugin High Patched: Yes CVE-2019-15868
CVE-2019-15868: Affiliates Manager <= 2.6.5 - Cross-Site Request Forgery

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.6.6. This makes it possible for unauthenticated attackers to perform unspecified modifications to the plugin settings granted they can trick a site administrator into perf...

Published
May 26, 2019
Patched Release
2.6.6
Affected Versions
Versions before 2.6.6
Next Step
Update to 2.6.6 or newer if supported.