WP Affiliate Platform

WP Affiliate Platform has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2024; all 12 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (58%). Other recurring categories include Cross-Site Request Forgery (CSRF).

Every one of the 12 issues recorded for WP Affiliate Platform has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, most of them (7) reported by Bob Matyas.

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage100%
Open

0

Fixed

12

Get automatic notifications for all WP Affiliate Platform vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-3898

WP Affiliate Platform <= 6.3.9 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

12 records
2024-07-08 00:00CVE-2024-5285
5.4
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5280
6.1
Medium
Felipe CaonYes
2024-06-22 00:00CVE-2024-5283
6.1
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5282
6.1
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5286
6.1
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5287
5.4
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5281
6.1
Medium
Bob MatyasYes
2024-06-22 00:00CVE-2024-5284
6.1
Medium
Bob MatyasYes
2022-11-08 00:00CVE-2022-3896
6.1
Medium
Marco WotschkaYes
2022-11-08 00:00CVE-2022-3897
5.5
Medium
Marco WotschkaYes
Showing 1–10 of 12 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C