PHP Object Injection Vulnerability in Affiliate Links Plugin for WordPress
CVE-2024-13556
Key Information:
- Vendor
- Wecantrack
- Status
- Affiliate Links: WordPress Plugin For Link Cloaking And Link Management
- Vendor
- CVE Published:
- 18 February 2025
Summary
The Affiliate Links plugin for WordPress is susceptible to a PHP Object Injection vulnerability due to the deserialization of untrusted input during file exports. This issue affects all versions up to and including 3.0.1, allowing unauthenticated attackers to inject a PHP object. While this vulnerability remains inert without the presence of a vulnerable PHP Object Injection chain from another plugin or theme, it poses a significant risk when such a chain exists. Exploiting this vulnerability could enable attackers to perform actions like deleting arbitrary files, accessing sensitive data, or executing malicious code through the compromised system.
Affected Version(s)
Affiliate Links: WordPress Plugin for Link Cloaking and Link Management * <= 3.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved