WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Affiliates Manager

Affiliates Manager plugin can help you manage an affiliate marketing program to drive more traffic and more sales to your site.

16Reported vulnerabilities
8.8Highest CVSS score
2.9.54Latest version
8,000+Active installs

What to do now

Update Affiliates Manager to 2.9.54 or later. 16 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-2798 High 8 1.0% Before 2.9.14 2.9.14 September 16, 2022
CVE-2021-24844 High 7.2 1.5% Before 2.8.7 2.8.7 November 8, 2021
CVE-2021-25078 Medium 6.1 2.3% Before 2.9.0 2.9.0 January 24, 2022
CVE-2022-2799 Medium 4.8 0.6% Before 2.9.14 2.9.14 September 16, 2022
CVE-2019-15868 High 8.8 0.7% Before 2.6.6 2.6.6 September 3, 2019
WF-ddd37b7a-3ef8-4269-ba3b-665ae34bde26 High 8.8 2.9.13 and earlier 2.9.14 August 16, 2022
CVE-2026-73355 High 7.5 0.4% 2.9.53 and earlier 2.9.54 August 18, 2026
CVE-2026-73358 High 7.2 0.2% 2.9.53 and earlier 2.9.54 August 18, 2026
CVE-2023-52130 Medium 6.5 0.2% 2.9.31 and earlier 2.9.32 December 28, 2023
WF-ecbb40a5-3e33-4084-a19b-daf014ce68c8 Medium 6.1 2.9.13 and earlier 2.9.14 August 16, 2022
WF-7ff58a34-93ab-4e51-b857-fed1107631ea Medium 6.1 Before 2.7.8 2.7.8 September 11, 2020
CVE-2026-52692 Medium 5.3 0.2% 2.9.50 and earlier 2.9.51 June 8, 2026
CVE-2023-52148 Medium 5.3 0.4% 2.9.30 and earlier 2.9.31 December 28, 2023
CVE-2026-57654 Medium 4.3 0.3% 2.9.49 and earlier 2.9.50 June 26, 2026
CVE-2024-0859 Medium 4.3 0.3% 2.9.34 and earlier 2.9.35 February 5, 2024
CVE-2023-28986 Medium 4.3 0.3% 2.9.20 and earlier 2.9.21 March 29, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.