Input validation vulnerability in Affiliates Manager 2.9.31

The Affiliates Manager plugin for WordPress is vulnerable to malicious attacks. This means that unauthenticated attackers may be able to manipulate certain aspects of the plugin. This includes approving, declining, or blocking affiliate applications, as well as managing the status of affiliates. To do this, the attackers would need to trick a site administrator into clicking on a link. Versions up to and including 2.9.31 of the plugin are affected. This is because the plugin does not always properly validate nonces which are used to help protect against malicious attacks.

Detected in:

Affiliates Manager fixed vulnerable versions: >= * <= 2.9.31

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.