Auto Affiliate Links <= 6.2.1.5 - Authenticated (Subscriber+) Plugin Settings Change

2023-02-06 00:00
Nguyen Anh Tien

Strategic Overview

Status
Patched in 6.2.1.6
Affected PluginAuto Affiliate Links
Affected Version<= 6.2.1.5
CVSS5.4Medium
CVECVE-2022-45840
View all Auto Affiliate Links vulnerabilities

Vulnerability Overview

The Auto Affiliate Links plugin for WordPress is vulnerable to improper access control via multiple AJAX actions in versions up to, and including, 6.2.1.5. This allows authenticated attackers with subscriber-level permissions or above to modify plugin settings such as adding exclusions for posts and words and to view statistics.

Technical Analysis

REMEDIATION: Update to version 6.2.1.6, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C