Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-06-12

CVE-2024-9838 - Auto Affiliate Links Plugin

The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

PLUGIN Auto Affiliate Links

CVE-2024-9838

MEDIUM CVSS 5.4 2025-05-15
Threat Entry Updated 2025-04-03

CVE-2024-1843 - Auto Affiliate Links Plugin

The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to posts.

PLUGIN Auto Affiliate Links

CVE-2024-1843

MEDIUM CVSS 4.3 2024-03-13
Scroll to top