PHP Object Injection Vulnerability in Affiliate Links Plugin for WordPress
CVE-2024-13556

9.8CRITICAL

Key Information:

Vendor
Wecantrack
Status
Affiliate Links: WordPress Plugin For Link Cloaking And Link Management
Vendor
CVE Published:
18 February 2025

Summary

The Affiliate Links plugin for WordPress is susceptible to a PHP Object Injection vulnerability due to the deserialization of untrusted input during file exports. This issue affects all versions up to and including 3.0.1, allowing unauthenticated attackers to inject a PHP object. While this vulnerability remains inert without the presence of a vulnerable PHP Object Injection chain from another plugin or theme, it poses a significant risk when such a chain exists. Exploiting this vulnerability could enable attackers to perform actions like deleting arbitrary files, accessing sensitive data, or executing malicious code through the compromised system.

Affected Version(s)

Affiliate Links: WordPress Plugin for Link Cloaking and Link Management * <= 3.0.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.