CVE Database /
CVE-2026-42653
CVE · High
CVE-2026-42653 — Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-42653
|
Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.7 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 1.2.7
|
1.2.7 |
2026-05-06 |
—
|
CVE-2026-42653
The SliceWP Affiliates plugin for WordPress contains a security flaw that allows malicious code to be embedded into the site, which can then run when users visit those pages, even if they're not logged in. This issue arises from inadequate checks on data coming into the plugin and insufficient protection against potentially hazardous content being displayed. The vulnerability affects versions of the plugin up through 1.2.6.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings