WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WC Affiliate – WooCommerce Affiliate Plugin

The most complete WooCommerce affiliate plugin - unlimited affiliates, real-time tracking, flexible commissions. Free to start.

4Reported vulnerabilities
8.8Highest CVSS score
3.9Latest version
200+Active installs

What to do now

Update WC Affiliate – WooCommerce Affiliate Plugin to 2.17 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-12321 High 7.1 0.3% Before 2.4 2.4 January 27, 2025
CVE-2025-47660 High 8.8 0.4% 2.16 and earlier 2.17 May 16, 2025
CVE-2024-12336 Medium 6.5 0.3% Before 2.6 2.6 March 15, 2025
CVE-2024-12334 Medium 6.1 0.3% Before 2.5 2.5 January 26, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.