Input validation vulnerability in Affiliates Manager 2.9.13

The Affiliates Manager plugin for WordPress is not secure enough in versions up to 2.9.13. This security issue makes it possible for unauthenticated attackers to delete affiliates and commissions without authorization if the attacker can trick a site administrator into clicking on a link. This is caused by the process_individual_action function not having the correct security measures in place.

Detected in:

Affiliates Manager fixed vulnerable versions: >= * <= 2.9.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.