CVE-2022-0634: ThirstyAffiliates < 3.10.5 - Subscriber+ unauthorized image upload + CSRF
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the tainsertexternalimage action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0634?
CVE-2022-0634 is considered a medium severity vulnerability due to its potential impact on user data.
How do I fix CVE-2022-0634?
To fix CVE-2022-0634, update the ThirstyAffiliates plugin to version 3.10.5 or later.
What are the consequences of CVE-2022-0634?
CVE-2022-0634 allows low-privilege users to add external images to affiliate links, potentially leading to misuse of the plugin.
Who is affected by CVE-2022-0634?
Any users with the ThirstyAffiliates plugin version prior to 3.10.5 are affected by CVE-2022-0634.
What type of vulnerability is CVE-2022-0634?
CVE-2022-0634 is an authorization and CSRF (Cross-Site Request Forgery) vulnerability.