CVE-2026-73355: WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Affected Software
1 affected component
WordPress Affiliates Manager plugin<=2.9.53
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Affiliates Manager pluginto a version that resolves this vulnerability.Fixed in 2.9.54
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The vulnerability is unauthenticated, and the attack vector is network-based with low attack complexity and no user interaction required.
2
What security impact is indicated by the available severity data?
Successful exploitation can result in high confidentiality impact and low availability impact. The CVSS vector indicates no integrity impact and a changed scope.