Input validation vulnerability in WP Affiliate Platform 6.5.0

The WP Affiliate Platform plugin for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions up to 6.5.0 and is caused by missing or incorrect validation when updating information. This means that attackers who are not logged in can change settings and insert harmful web scripts by tricking a site administrator into clicking on a link.

Detected in:

WP Affiliate Platform fixed vulnerable versions: >= * <= 6.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.