WordPress Auto Affiliate Links plugin <= 6.2.1.5 - Unauth. Broken Access Control vulnerability
CVE-2022-45840

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 December 2024

Summary

The Auto Affiliate Links plugin developed by Lucian Apostol is susceptible to a missing authorization vulnerability, which arises from incorrectly configured access control security levels. This vulnerability allows attackers to bypass authentication mechanisms, potentially granting unauthorized access to sensitive functionalities within the plugin. Affected versions range from unnumbered releases up to and including version 6.2.1.5. Site administrators should take immediate action to review their configuration settings and apply any necessary updates to safeguard their systems against potential exploitation.

Affected Version(s)

Auto Affiliate Links <= 6.2.1.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Anh Tien (Patchstack Alliance)
.