Extension WordPress
Vulnérabilités WP Affiliate Platform
Cette page rassemble les failles publiées pour WP Affiliate Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Affiliate Platform
12 fiches
WP Affiliate Platform <= 6.5.1 – Cross-Site Request Forgery to Afilliate Deletion
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.1. This is due to missing or incorrect nonce validation on the affiliate 'delete' functionality. This makes it…
*-6.5.1
6.5.2
08/07/2024
WP Affiliate Platform <= 6.5.0 – Cross-Site Request Forgery to Cross-Site Scripting
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.0. This is due to missing or incorrect nonce validation on the 'info_update' functionality. This makes it possible…
*-6.5.0
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Cross-Site Request Forgery to Profile Update
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the profile update functionality. This makes it possible…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 6.5.1 (exclusive). This is due to missing or incorrect nonce validation on the wp_aff_platform_settings page. This makes it possible for…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Reflected Cross-Site Scripting via Lead Editing
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wp_aff_referrer' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Reflected Cross-Site Scripting via Affiliate Editing
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editaff' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Reflected Cross-Site Scripting via Registration Form
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'afirstname' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform < 6.5.1 – Reflected Cross-Site Scripting via Banner Editing
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'editrecord' parameter in all versions up to 6.5.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 6.5.1)
6.5.1
22/06/2024
WP Affiliate Platform <= 6.3.9 – Cross-Site Request Forgery
The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes…
*-6.3.9
6.4.0
08/11/2022
WP Affiliate Platform <= 6.3.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-6.3.9
6.4.0
08/11/2022
WP Affiliate Platform <= 6.3.9 – Reflected Cross-Site Scripting
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-6.3.9
6.4.0
08/11/2022
WP Affiliate Platform <= 6.3.8 – Reflected Cross-Site Scripting
The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in the 'login.php' file due to insufficient input sanitization and output escaping. This affects versions up to and including 6.3.8. This…
*-6.3.8
6.3.9
01/05/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.