Executive brief
The Affiliates Manager plugin for WordPress, which helps businesses manage affiliate marketing programs, contains a security flaw that exposes sensitive information. An unauthorized person can access data that should be private without needing a password or any special account. This exposed information could be used by attackers to further compromise the website or its users.
Technical details
The Affiliates Manager plugin for WordPress (versions <= 2.9.50) is vulnerable to an insertion of sensitive information into sent data (CWE-201). This flaw allows an unauthenticated remote attacker to access sensitive information that is typically restricted to authorized users. The vulnerability stems from improper data handling within the plugin's components, enabling data leakage over the network without requiring user interaction or specific privileges. Attackers can leverage this exposed data to facilitate further attacks against the WordPress environment. The issue is resolved in version 2.9.51.
Affected products
- Affiliates Manager Affiliates Manager <= 2.9.50
Timeline
- 2026-05-23: other: Reported by researcher dodoh4t
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD
- 2026-06-08: patched: Version 2.9.51 released to address the vulnerability