Savyour Affiliate Partner
Savyour Affiliate Partner has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Savyour Affiliate Partner has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. Savyour Affiliate Partner is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2025-48306Savyour Affiliate Partner <= 2.1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Savyour Affiliate Partner
Author
developers savyour
Plugin key is installed on header or Cart of host page. The plugin will help to embed a handshaking code in the host website that works in a synchronize method having acknowledgment of received or sent information. When a Savyour user places an order on the website, the plugin would transfer a certain set of information. This information would be about the orders status, placed or confirmed. The information recieved will be in terms of Order IDs that are posted and their respective order status. The order status might be incomplete or complete. More about this Plugin This plug allows sharing of certain data about the orders placed The Plugin activates when a Savyour user checks into our partner’s website, or proceeds to the cart. When Savyour user accesses our partner website or cart, the plugin is responsible to enable the handshaking code. The handshaking code is responsible of making the exchange od certain data possible The data shared will be a list of users visiting our partner’s website The data will be categorized in to savyour users and others The data will also tell if status of orders placed at the partner website It categorizes users coming from savyour as per their order status These statuses could be users who completed a transaction and checked out their cart Those who filled their cart and did not check out Those who browsed through the website, but didnt make any purchase or added any items into the cart.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C