Auto Affiliate Links <= 6.2.1.5 - Authenticated (Subscriber+) Plugin Settings Change
2023-02-06 00:00
Nguyen Anh TienStrategic Overview
StatusPatched in 6.2.1.6
Affected PluginAuto Affiliate Links
Affected Version
<= 6.2.1.5CVSS5.4Medium
CVE
CVE-2022-45840Vulnerability Overview
The Auto Affiliate Links plugin for WordPress is vulnerable to improper access control via multiple AJAX actions in versions up to, and including, 6.2.1.5. This allows authenticated attackers with subscriber-level permissions or above to modify plugin settings such as adding exclusions for posts and words and to view statistics.
Technical Analysis
REMEDIATION: Update to version 6.2.1.6, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C