WordPress & WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass to Account Takeover and Privilege Escalation
criticalThe WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible f...
- CVSS:
- 9.8
- Affected:
- up to 8.4.1
- Fixed in:
- 8.5.0
- Disclosed:
- Sep 30, 2024