PatchSiren

AffiliateWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AffiliateWP CVE published 2026-08-06

CVE-2026-65515

CVE-2026-65515 is an unauthenticated Cross Site Scripting (XSS) vulnerability in AffiliateWP plugin versions <= 2.35.0. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. This vulnerability affects WordPress installations with AffiliateWP plugin versions <= 2.35.0. The CVE record was published on 2026-08-06T15:17:15.360Z and has not been modified since then. Defenders should pri [truncated]