Unauthorized Modification of Data in WooCommerce Cloak Affiliate Links Plugin
CVE-2024-1308

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 April 2024

Summary

The WooCommerce Cloak Affiliate Links plugin for WordPress is susceptible to unauthorized data modification due to a lack of proper capability checks in the 'permalink_settings_save' function present in all versions up to and including 1.0.33. This vulnerability permits unauthenticated attackers to alter the affiliate permalink base, redirecting traffic to malicious sites through the compromised affiliate links. As a result, website owners relying on this plugin must address this issue to protect their website’s integrity and safeguard users from potential phishing attacks and other security risks.

Affected Version(s)

WooCommerce Cloak Affiliate Links * <= 1.0.33

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.