← WordPress Vulnerabilities
WordPress security by component

AffiliateX

AffiliateX is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: affiliatex

CVE-2026-65558: AffiliateX permits unauthenticated server-side request forgery

AffiliateX through 2.3.5 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.

PublishedJul 27, 2026
Known safe version2.3.6
Safe version
Jul 27, 2026 CVE-2026-65558
AffiliateX permits unauthenticated server-side request forgery
AffiliateX through 2.3.5 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
2.3.6
CVE5.4
NVDPending
Jan 06, 2026 CVE-2025-69346
AffiliateX: A security weakness
AffiliateX is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 29, 2024 CVE-2024-49692
AffiliateX: Cross-site scripting
AffiliateX is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4