LWS Affiliation
LWS Affiliation has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), PHP Remote File Inclusion.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, one record each. LWS Affiliation is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-57934LWS Affiliation <= 2.3.6 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

LWS Affiliation
Author
Aurélien LWS
This plugin, created by LWS, allows you to easily add banners and widgets such as domain name availability search or a summary table of our hosting plans on your website. Enjoy our affiliate program and earn money! Key Features Major features in LWS Affiliation include: Add an affiliate banner in one click. Add a customizable domain name search widget. Add a table of our hosting offers (shared hosting, VPS, e-commerce, cloud, etc…). Follow the perfomances of your widgets on your website You will need a LWS Affiliation account to use it. This plugin is ideal for fans of LWS services and especially Best Sellers shared web hosting , WordPress hosting, cPanel hosting.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C