Open Redirect Vulnerability in Affiliate Sales Plugin for WordPress by Google
CVE-2024-12561
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 May 2025
What is CVE-2024-12561?
The Affiliate Sales plugin for WordPress, associated with Google Analytics, is susceptible to an Open Redirect vulnerability. This flaw arises from inadequate validation of the redirect URL provided through the 'afflink' parameter. As a result, malicious actors can exploit this vulnerability to redirect unsuspecting users to harmful websites after successfully manipulating them into clicking on links associated with their redirect requests. Website owners should ensure their plugins are updated and secure to prevent any potential exploitation.
Affected Version(s)
Affiliate Sales in Google Analytics and other tools * <= 1.4.9