First published: Mon Apr 25 2022(Updated: )
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Caseproof Thirstyaffiliates Affiliate Link Manager | <3.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0398 is classified as a medium severity vulnerability due to the potential for unauthorized affiliate link creation.
To fix CVE-2022-0398, update the ThirstyAffiliates Affiliate Link Manager plugin to version 3.10.5 or later.
Any authenticated user, including subscribers, can be affected by CVE-2022-0398 if they have access to the WordPress admin interface.
CVE-2022-0398 allows unauthorized users to create arbitrary affiliate links, potentially leading to unauthorized redirection and financial loss.
Currently, the only effective workaround for CVE-2022-0398 is to upgrade the plugin to the latest version.