ARS Affiliate Page Plugin
ARS Affiliate Page Plugin has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for ARS Affiliate Page Plugin has a vendor fix available, so running the current release closes it.
All of these findings were reported by Le Ngoc Anh. ARS Affiliate Page Plugin is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-12098ARS Affiliate Page Plugin <= 2.0.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

ARS Affiliate Page Plugin
Author
ARS Developer
This plugin allows ARS clients to easily add Sell My Car, Donate My Car and Recycle My Car content to their wordpress site via shortcodes. Once the plugin is set up, simply add a shortcode to a page and the html content for the ARS affilaite program will be generated and displayed, including links to https://www.youcallwehaul.com and https://www.cardonationwizard.com. Privacy User Data: This plugin does not collect any user data. Cookies: This plugin does not use any cookies. Services: This plugin does not connect to any third-party locations or services. It simply generates links that include your referal code to https://www.youcallwehaul.com (sell_car_html shortcode) and https://www.cardonationwizard.com (donate_my_car shortcode).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C