Tapfiliate
Tapfiliate has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Tapfiliate has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Tapfiliate is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-58689Tapfiliate <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Tapfiliate
Author
Tapfiliate
Easily integrate Tapfiliate with WordPress and add tracking codes to any page. Tapfiliate allows you to easily create, track and manage your own affiliate marketing and referral programs. Our affiliate tracking software integrates seamlessly with WordPress, WooCommerce, WooCommerce Subscriptions and WP Easy Cart, so you can begin using affiliate marketing to grow your business in just minutes. For a complete guide for how to use Tapfiliate, visit Tapfiliate’s Developer Docs. Some Key Features Automatic integration with WordPress Easy management with automated workflows and triggers Individual affiliate portals with branded dashboard One-Click social media sharing with images, deeplinks, banners, or video Customizable commissions and bonus structures White labelled affiliate pages that match your brand and domain And great customer support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C