WordPress Auto Affiliate Links plugin <= 6.2.1.5 - Unauth. Broken Access Control vulnerability
CVE-2022-45840
6.5MEDIUM
What is CVE-2022-45840?
The Auto Affiliate Links plugin developed by Lucian Apostol is susceptible to a missing authorization vulnerability, which arises from incorrectly configured access control security levels. This vulnerability allows attackers to bypass authentication mechanisms, potentially granting unauthorized access to sensitive functionalities within the plugin. Affected versions range from unnumbered releases up to and including version 6.2.1.5. Site administrators should take immediate action to review their configuration settings and apply any necessary updates to safeguard their systems against potential exploitation.
Affected Version(s)
Auto Affiliate Links <= 6.2.1.5