Cloak Affiliate Links for WooCommerce
Cloak Affiliate Links for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Access Control.
Every one of the 2 issues recorded for Cloak Affiliate Links for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Cloak Affiliate Links for WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-1308WooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink Modification
Read the full analysisVulnerability Records
Cloak Affiliate Links for WooCommerce
Author
datafeedr
The Cloak Affiliate Links for WooCommerce plugin allows you to mask all external links in your WooCommerce store. For example, change this… merchant.com/index.php?aff_id=123&product_id=456 … into this: yoursite.com/go/123 Configure the status code for the redirect to either 301, 302 or 307. The plugin also adds a “Disallow” to your robots.txt file to prevent bots from following those external links.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C