Input validation vulnerability in Affiliates Manager 2.8.6

The Affiliates Manager WordPress plugin had a vulnerability in versions before 2.8.7. This vulnerability could allow someone to cause harm to the website by using an SQL Injection. An SQL Injection is an attack that can use malicious code to manipulate data within a database. This vulnerability was caused by the plugin not properly checking the orderby parameter before using it in an SQL statement in the admin dashboard.

Detected in:

Affiliates Manager fixed vulnerable versions: >= * <= 2.8.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.