Extension WordPress
Vulnérabilités affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display
Cette page rassemble les failles publiées pour affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display
14 fiches
affiliate-toolkit <= 3.8.5 – Authenticated (Editor+) Remote Code Execution
The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into…
*-3.8.4
Non indiqué
26/05/2026
affiliate-toolkit <= 3.7.3 – Cross-Site Request Forgery
The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.3. This is due to missing or incorrect nonce validation on a function. This…
*-3.7.3
3.7.4
22/04/2025
affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping…
*-3.7.0
3.7.1
23/01/2025
affiliate-toolkit <= 3.6.7 – Reflected Cross-Site Scripting
The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.6.7
3.6.8
20/11/2024
affiliate-toolkit <= 3.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via atkp_product Shortcode
The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-3.6.5
3.6.6
28/10/2024
affiliate-toolkit <= 3.5.5 – Unauthenticated Full Path Dislcosure
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is due display_errors being set to true . This makes it possible for unauthenticated…
*-3.5.5
3.6
08/08/2024
affiliate-toolkit <= 3.4.4 – Unauthenticated Sensitive Information Exposure via Logs
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…
*-3.4.4
3.4.5
20/06/2024
affiliate-toolkit <= 3.4.5 – Authenticated (Author+) Stored Cross-Site Scripting via ratings
The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various ratings postmeta parameters in versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.4.5
3.4.6
25/03/2024
affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 – Missing Authorization via atkp_import_product
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated…
*-3.5.4
3.5.5
07/03/2024
affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 – Missing Authorization via atkp_create_list
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated…
*-3.5.4
3.5.5
07/03/2024
affiliate-toolkit <= 3.4.2 – Unauthenticated Server-Side Request Forgery
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.2 via the affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint. This makes it possible for unauthenticated attackers to make web requests…
*-3.4.2
3.4.3
11/12/2023
affiliate-toolkit – WordPress Affiliate Plugin <= 3.4.3 – Reflected Cross-Site Scripting via keyword
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the keyword parameter in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.4.3
3.4.4
28/11/2023
affiliate-toolkit – WordPress Affiliate Plugin <= 3.3.9 – Open Redirect via atkpout.php
The affiliate-toolkit – WordPress Affiliate Plugin is vulnerable to Open Redirect in versions up to, and including, 3.3.9. This is due to insufficient validation on the redirect url supplied via the 'url' parameter in atkpout.php. This makes it…
*-3.3.9
3.4.0
06/10/2023
affiliate-toolkit – WordPress Affiliate Plugin <= 3.3.3 – Authenticated (Editor+) Stored Cross-Site Scripting
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post settings in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.3.3
3.3.4
30/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.