Skip to main content

Vendor/product archive

tipsandtricks-hq / wp_affiliate_platform CVEs

Beta · best-effort

11 CVEs tagged to tipsandtricks-hq / wp_affiliate_platform0 Critical, 2 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2024-5285

Published Jul 29, 2024

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change del…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5287

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5286

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5284

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to ma…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5283

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5282

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5281

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5280

Published Jul 13, 2024

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to ma…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3898

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce valid…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3897

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient inpu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3896

Published Nov 29, 2022

The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insuffici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1