cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forslicewp slicewp

Direction: descending
May 13, 2026

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2026-42653

CVE, Research URL

CVE-2026-42653

Date
-
Research Description
Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.7 CVE-2026-42653
Affected versions
max 1.2.7.
Status
vulnerable
May 07, 2026

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2026-6672

CVE, Research URL

CVE-2026-6672

Date
May 06, 2026
Research Description
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the 'slicewp_affiliate_url' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.2.8.
Status
vulnerable
Dec 18, 2024

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2024-12454

CVE, Research URL

CVE-2024-12454

Date
Dec 18, 2024
Research Description
The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.23. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.24.
Status
vulnerable
Oct 03, 2024

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2024-47388

CVE, Research URL

CVE-2024-47388

Date
Oct 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.
Affected versions
max 1.1.19.
Status
vulnerable
Sep 14, 2024

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2024-8714

CVE, Research URL

CVE-2024-8714

Date
Sep 13, 2024
Research Description
The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.20. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.1.21.
Status
vulnerable
Jun 07, 2024

WordPress Affiliates Plugin — SliceWP Affiliates # a3180e788ea2fcfcd8d3bf7c17348a519c805bf7

Date
Aug 09, 2021
Research Description
Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.0.46 WordPress SliceWP plugin <= 1.0.45 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress SliceWP plugin (versions <= 1.0.45).
Affected versions
max 1.0.46.
Status
vulnerable

WordPress Affiliates Plugin — SliceWP Affiliates # CVE-2024-34413

CVE, Research URL

CVE-2024-34413

Date
May 07, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Stored XSS.This issue affects SliceWP: from n/a through 1.1.10.
Affected versions
max 1.1.11.
Status
vulnerable