Known Vulnerabilities for Affiliates Mod by Punres
Listed below are 1 of the newest known vulnerabilities associated with "Affiliates Mod" by "Punres".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57654 json | Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions. | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-52692 json | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49068 json | Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-40770 json | Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-24989 json | Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This iss... | Not Provided | 2026-03-25 | 2026-04-24 |
| CVE-2026-8837 json | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Sh... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-6672 json | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shor... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2025-62884 json | Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functiona... | Not Provided | 2025-10-27 | 2026-04-27 |
| CVE-2025-30631 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sal... | Not Provided | 2026-01-06 | 2026-04-28 |
| CVE-2025-30628 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliat... | Not Provided | 2025-12-31 | 2026-04-28 |