Known vulnerabilities, PHP compatibility and safer alternatives for the Wp Auto Affiliate Links WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
- Slug:
wp-auto-affiliate-links
Maintenance status
Known vulnerabilities
8 known CVEs on file for Wp Auto Affiliate Links.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-24592
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.8.9 |
Missing Authorization |
Medium
5.3
|
< 6.8.9
|
6.8.9 |
2026-05-25 |
—
|
|
CVE-2026-7330
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.8.8.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.2
|
< 6.8.8.1
|
6.8.8.1 |
2026-05-07 |
—
|
|
CVE-2024-34386
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.6
|
< 6.4.4
|
6.4.4 |
2024-05-06 |
—
|
|
CVE-2024-1843
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.3.1 |
Missing Authorization |
Medium
4.3
|
< 6.4.3.1
|
6.4.3.1 |
2024-03-11 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8 |
— |
Unknown
|
< 6.4.2.8
|
6.4.2.8 |
2024-01-09 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6 |
— |
Unknown
|
< 6.4.2.6
|
6.4.2.6 |
2023-11-20 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6 |
— |
Unknown
|
< 6.4.2.6
|
6.4.2.6 |
2023-11-20 |
—
|
|
CVE-2023-47652
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.5 |
Cross-Site Request Forgery (CSRF) |
High
7.1
|
< 6.4.2.5
|
6.4.2.5 |
2023-11-07 |
—
|
CVE-2026-24592
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.8.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Source:
Wordfence
CVE-2026-7330
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(), where the stored value is echoed directly into an anchor element's href attribute and inner text without esc_url(), esc_attr(), or esc_html(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the admin statistics page that execute in an administrator's browser when the page is visited, leveraging a publicly exposed nonce and an unauthenticated AJAX endpoint registered via the wp_ajax_nopriv_ hook.
Source:
CVE.org
CVE-2024-34386
The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
Wordfence
CVE-2024-1843
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.4.3.1).
Lucio Sá discovered and reported this Broken Access Control vulnerability in WordPress Auto Affiliate Links Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 6.4.3.1.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.2.7. This is due to missing or incorrect nonce validation on the wpaal_stats() function. This makes it possible for unauthenticated attackers to reset stats via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.2.5. This is due to missing or incorrect nonce validation on several functions such as aal_exclude_terms_actions and aal_exclude_words_actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.4.2.6).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Auto Affiliate Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.4.2.6.
Source:
Patchstack
CVE-2023-47652
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.2.4. This is due to missing or incorrect nonce validation on several functions such as aalUpdateExcludePosts(). This makes it possible for unauthenticated attackers to update plugin settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
+ 9 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-25973
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.3 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 6.3.0.3
|
6.3.0.3 |
2023-02-22 |
—
|
|
CVE-2022-45840
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.2.1.6 |
Missing Authorization |
Medium
6.5
|
< 6.2.1.6
|
6.2.1.6 |
2023-02-06 |
—
|
|
CVE-2023-22689
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.1 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 6.3.0.1
|
6.3.0.1 |
2023-02-02 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0 |
— |
Unknown
|
< 5.0
|
5.0 |
2015-07-15 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0 |
— |
Unknown
|
< 5.0
|
5.0 |
2015-07-15 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.7 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Medium
5.4
|
< 6.4.7
|
6.4.7 |
0000-00-00 |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0 |
— |
Unknown
|
< 5.0
|
5.0 |
— |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6 |
— |
Unknown
|
< 6.4.2.6
|
6.4.2.6 |
— |
—
|
|
—
|
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8 |
— |
Unknown
|
< 6.4.2.8
|
6.4.2.8 |
— |
—
|
CVE-2023-25973
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.3.0.3).
Rio Darmawan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Auto Affiliate Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 6.3.0.3.
Source:
Patchstack
CVE-2022-45840
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.2.1.6).
Tien Nguyen Anh discovered and reported this Privilege Escalation vulnerability in WordPress Auto Affiliate Links Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website. This vulnerability has been fixed in version 6.2.1.6.
Source:
Patchstack
CVE-2023-22689
The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.0.1. This is due to missing or incorrect nonce validation on the aalDeleteLink() function. This makes it possible for unauthenticated attackers to delete links via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
Because of this vulnerability, authenticated users can execute arbitrary SQL commands.
Update the plugin.
Source:
Patchstack
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
The Auto Affiliate Links plugin for WordPress is vulnerable to multiple SQL Injections via the 'aal_massstring' and 'aalorder' parameters in versions before 5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
Wordfence
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.7
The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Source:
Wordfence
Auto Affiliate Links [wp-auto-affiliate-links] < 5.0
The Auto Affiliate Links WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.
Source:
WPScan
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.6
The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Source:
WPScan
Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.2.8
The plugin is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.2.7. This is due to missing or incorrect nonce validation on the wpaal_stats() function. This makes it possible for unauthenticated attackers to reset stats via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
WPScan
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.