Extension WordPress

Vulnérabilités affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

Cette page rassemble les failles publiées pour affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
13Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

14 fiches

CVE-2026-6169 Élevée · 7,2
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.8.5 – Authenticated (Editor+) Remote Code Execution

The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into…

Versions affectées

*-3.8.4

Correctif

Non indiqué

Publication

26/05/2026

CVE-2026-15296 Moyenne · 6,4
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping…

Versions affectées

*-3.7.0

Correctif

3.7.1

Publication

23/01/2025

CVE-2024-10675 Moyenne · 6,1
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.6.7 – Reflected Cross-Site Scripting

The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

20/11/2024

CVE-2024-10227 Moyenne · 6,4
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via atkp_product Shortcode

The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-3.6.5

Correctif

3.6.6

Publication

28/10/2024

CVE-2024-6562 Moyenne · 5,3
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.5.5 – Unauthenticated Full Path Dislcosure

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is due display_errors being set to true . This makes it possible for unauthenticated…

Versions affectées

*-3.5.5

Correctif

3.6

Publication

08/08/2024

CVE-2024-37205 Moyenne · 5,3
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.4.4 – Unauthenticated Sensitive Information Exposure via Logs

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

20/06/2024

CVE-2024-29817 Moyenne · 6,4
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.4.5 – Authenticated (Author+) Stored Cross-Site Scripting via ratings

The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various ratings postmeta parameters in versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-3.4.5

Correctif

3.4.6

Publication

25/03/2024

CVE-2024-2298 Moyenne · 4,3
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 – Missing Authorization via atkp_import_product

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated…

Versions affectées

*-3.5.4

Correctif

3.5.5

Publication

07/03/2024

CVE-2024-1851 Moyenne · 6,3
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 – Missing Authorization via atkp_create_list

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated…

Versions affectées

*-3.5.4

Correctif

3.5.5

Publication

07/03/2024

CVE-2023-5877 Moyenne · 6,5
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit <= 3.4.2 – Unauthenticated Server-Side Request Forgery

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.2 via the affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint. This makes it possible for unauthenticated attackers to make web requests…

Versions affectées

*-3.4.2

Correctif

3.4.3

Publication

11/12/2023

CVE-2023-46086 Moyenne · 6,1
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WordPress Affiliate Plugin <= 3.4.3 – Reflected Cross-Site Scripting via keyword

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the keyword parameter in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.4.3

Correctif

3.4.4

Publication

28/11/2023

CVE-2023-45105 Faible · 3,4
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WordPress Affiliate Plugin <= 3.3.9 – Open Redirect via atkpout.php

The affiliate-toolkit – WordPress Affiliate Plugin is vulnerable to Open Redirect in versions up to, and including, 3.3.9. This is due to insufficient validation on the redirect url supplied via the 'url' parameter in atkpout.php. This makes it…

Versions affectées

*-3.3.9

Correctif

3.4.0

Publication

06/10/2023

CVE-2023-23786 Moyenne · 5,5
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

affiliate-toolkit – WordPress Affiliate Plugin <= 3.3.3 – Authenticated (Editor+) Stored Cross-Site Scripting

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post settings in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.3.3

Correctif

3.3.4

Publication

30/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités