CVE-2026-73358: WordPress Affiliates Manager plugin <= 2.9.53 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Affiliates Manager pluginto a version that resolves this vulnerability.Fixed in 2.9.54 - Compensating control
If immediate upgrade to at least 2.9.54 is not possible, restrict exposure of the site that runs the WordPress Affiliates Manager plugin (e.g., limit public access) until the plugin is updated.
Event History
Frequently Asked Questions
Which deployments are affected?
Sites running Affiliates Manager version 2.9.53 or earlier are affected according to the available data. The issue is in the WordPress plugin, so exposure depends on that plugin being installed at one of those versions.
What does an attacker need to exploit this issue?
An attacker does not need to authenticate, but exploitation requires user interaction. The supplied vector indicates the attack can be delivered remotely over the network.