Extension WordPress
Vulnérabilités ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
Cette page rassemble les failles publiées pour ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
5 fiches
ThirstyAffiliates <= 3.11.9 – Cross-Site Request Forgery
The ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.11.9. This is due to missing or incorrect nonce validation…
*-3.11.9
3.11.10
02/02/2026
ThirstyAffiliates <= 3.11.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ThirstyAffiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.11.8
3.11.9
15/12/2025
ThirstyAffiliates Affiliate Link Manager <= 3.10.4 – Subscriber+ Arbitrary Affiliate Links Creation
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site Request Forgery checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could…
*-3.10.4
3.10.5
10/04/2022
ThirstyAffiliates Affiliate Link Manager <= 3.10.4 – Authorization Bypass and Cross-Site Request Forgery
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate…
*-3.10.4
3.10.5
10/04/2022
ThirstyAffiliates Affiliate Link Manager <= 3.9.2 – Stored Cross-Site Scripting
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.
*-3.9.2
3.9.3
22/05/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.