Unauthorized Modification of Data in WooCommerce Cloak Affiliate Links Plugin
CVE-2024-1308
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-1308?
The WooCommerce Cloak Affiliate Links plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the 'permalink_settings_save' function present in all versions up to and including 1.0.33. This vulnerability permits unauthenticated attackers to alter the affiliate permalink base, redirecting traffic to malicious sites through the compromised affiliate links. As a result, website owners relying on this plugin must address this issue to protect their website’s integrity and safeguard users from potential phishing attacks and other security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce Cloak Affiliate Links * <= 1.0.33
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved