The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to posts.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flamescorpion
Flamescorpion auto Affiliate Links |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:flamescorpion:auto_affiliate_links:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Flamescorpion
Flamescorpion auto Affiliate Links |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T18:56:22.367Z
Reserved: 2024-02-23T15:11:17.559Z
Link: CVE-2024-1843

Updated: 2024-08-01T18:56:22.367Z

Status : Analyzed
Published: 2024-03-13T16:15:27.550
Modified: 2025-04-03T12:57:43.613
Link: CVE-2024-1843

No data.