plugin

Affiliate For Woocommerce Vulnerabilities

2 known security issues reported for the Affiliate For Woocommerce WordPress plugin. Most recent disclosed Aug 1, 2022.

1 high 1 medium

Running Affiliate For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Affiliate For WooCommerce premium <= 4.7.0 - Authenticated Insecure Direct Object Reference

high

This plugin Affiliate For WooCommerce premium for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.7.0. This makes it possible for attackers to change the PayPal email address that receives payments.

CVSS:
7.5
Affected:
up to 4.7.0
Fixed in:
4.8.0
Disclosed:
Aug 1, 2022

CVE-2022-36284 on NVD →

Affiliate For WooCommerce <= 4.7.0 - Missing Authorization

medium

The Affiliate For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks function in versions up to, and including, 4.7.0. This makes it possible for authenticated attackers with minimal permissions, such as an affiliate, to make unauthorized changes to the site.

CVSS:
5.4
Affected:
up to 4.7.0
Fixed in:
4.8.0
Disclosed:
Aug 1, 2022

CVE-2022-25649 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database