VYPR

Post Affiliate Pro

by WordPress

CVEs (2)

  • CVE-2026-2290LowMar 21, 2026
    risk 0.25cvss 3.8epss 0.00

    The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound…

  • CVE-2023-38482Sep 3, 2023
    risk 0.00cvss epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QualityUnit Post Affiliate Pro plugin <= 1.25.0 versions.