Input validation vulnerability in Affiliate Power – Sales Tracking for Affiliate Marketers 2.2.0

The Affiliate Power – Sales Tracking for Affiliate Marketers plugin for WordPress is vulnerable to a type of security threat known as Reflected Cross-Site Scripting. This threat can be found in versions 2.2.0 and earlier of the plugin. It occurs when the plugin does not properly sanitize or escape the ‘page’ parameter. This can allow attackers to inject malicious web scripts into pages that will be executed if a user is tricked into clicking on a link.

Detected in:

Affiliate Power – Sales Tracking for Affiliate Marketers fixed vulnerable versions: >= * <= 2.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.