CVE-2025-8877 | AffiliateWP Plugin up to 2.28.2 on WordPress ajax_get_affiliate_id_from_login sql injection (EUVD-2025-31707)
A vulnerability marked as critical has been reported in AffiliateWP Plugin up to 2.28.2 on WordPress. This affects the function ajax_get_affiliate_id_from_login. Performing manipulation results in sql injection.
This vulnerability is known as CVE-2025-8877. Remote exploitation of the attack is possible. No exploit is available.