Unauthorized Modification of Data in WooCommerce Cloak Affiliate Links Plugin
CVE-2024-1308
7.5HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 April 2024
Summary
The WooCommerce Cloak Affiliate Links plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the 'permalink_settings_save' function present in all versions up to and including 1.0.33. This vulnerability permits unauthenticated attackers to alter the affiliate permalink base, redirecting traffic to malicious sites through the compromised affiliate links. As a result, website owners relying on this plugin must address this issue to protect their website’s integrity and safeguard users from potential phishing attacks and other security risks.
Affected Version(s)
WooCommerce Cloak Affiliate Links * <= 1.0.33
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci