Affiliate For WooCommerce premium <= 4.7.0 - Authenticated Insecure Direct Object Reference
high
This plugin Affiliate For WooCommerce premium for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.7.0. This makes it possible for attackers to change the PayPal email address that receives payments.
- CVSS:
- 7.5
- Affected:
- up to 4.7.0
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 1, 2022
CVE-2022-36284 on NVD →
Affiliate For WooCommerce <= 4.7.0 - Missing Authorization
medium
The Affiliate For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks function in versions up to, and including, 4.7.0. This makes it possible for authenticated attackers with minimal permissions, such as an affiliate, to make unauthorized changes to the site.
- CVSS:
- 5.4
- Affected:
- up to 4.7.0
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 1, 2022
CVE-2022-25649 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database