PLUGIN SECURITY
Is Slicewp safe?
SliceWP is the quickest and easiest WordPress affiliates plugin for building your affiliate program. Track affiliate commissions, easily pay your affi …
What this plugin does
- Slug:
slicewp - Author: iova.mihai
- 10000+ active installs
- 98/100 rating (108 reviews on wordpress.org)
- 397676 all-time downloads
- On WordPress.org since 2020-01-03
affiliateaffiliate programaffiliatesaffiliates programwoocommerce affiliates
Maintenance status
- Latest known version: 1.2.10
- Last updated: 2026-08-21 1:50pm GMT
- Tested up to WordPress: 7.1.0
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
6 known CVEs on file for Slicewp. Reported between 2021 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-42653 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.2.7 | 1.2.7 | 2026-05-06 | ✓ fixed in latest |
| CVE-2026-6672 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 1.2.8 | 1.2.8 | 2026-05-05 | ✓ fixed in latest |
| CVE-2024-12454 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.1.24 | Cross-Site Request Forgery (CSRF) | Medium 6.1 | < 1.1.24 | 1.1.24 | 2024-12-17 | ✓ fixed in latest |
| CVE-2024-47388 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.1.19 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 1.1.19 | 1.1.19 | 2024-09-30 | ✓ fixed in latest |
| CVE-2024-8714 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.1.21 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.1.21 | 1.1.21 | 2024-09-12 | ✓ fixed in latest |
| CVE-2024-34413 | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.1.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 1.1.11 | 1.1.11 | 2024-05-06 | ✓ fixed in latest |
| — | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.0.46 | — | Unknown | < 1.0.46 | 1.0.46 | 2021-08-09 | ✓ fixed in latest |
| — | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.0.46 | — | Unknown | < 1.0.46 | 1.0.46 | 2021-08-09 | ✓ fixed in latest |
+ 2 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.0.46 | — | Unknown | < 1.0.46 | 1.0.46 | — | ✓ fixed in latest |
| — | SliceWP < 1.0.46 - Reflected Cross-Site Scripting (XSS) | — | Unknown | < 1.0.46 | 1.0.46 | — | ✓ fixed in latest |
How to fix it
Keep Slicewp updated — 1.2.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Advanced Ads – Ad Manager & AdSense — 100000+ active installs — 98/100 (1461)
- Pochipp — 20000+ active installs — 84/100 (5) — max PHP 8.4
- Meks Easy Ads Widget — 10000+ active installs — 82/100 (14)
- Meks ThemeForest Smart Widget — 10000+ active installs — 100/100 (1)
- AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking — 9000+ active installs — 90/100 (34)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.