First published: Mon Apr 25 2022(Updated: )
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Caseproof Thirstyaffiliates Affiliate Link Manager | <3.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0634 is considered a medium severity vulnerability due to its potential impact on user data.
To fix CVE-2022-0634, update the ThirstyAffiliates plugin to version 3.10.5 or later.
CVE-2022-0634 allows low-privilege users to add external images to affiliate links, potentially leading to misuse of the plugin.
Any users with the ThirstyAffiliates plugin version prior to 3.10.5 are affected by CVE-2022-0634.
CVE-2022-0634 is an authorization and CSRF (Cross-Site Request Forgery) vulnerability.