First published: Fri Dec 13 2024(Updated: )
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Auto Affiliate Links by Lucian Apostol | <=6.2.1.5 | |
WordPress Auto Affiliate Links | <=6.2.1.5 |
Update the WordPress Auto Affiliate Links plugin to the latest available version (at least 6.2.1.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45840 is considered a medium severity vulnerability due to its potential for unauthorized access across wrongly configured access controls.
To fix CVE-2022-45840, ensure that you update Auto Affiliate Links to the latest version released after 6.2.1.5 and review your access control configurations.
CVE-2022-45840 affects all versions of Auto Affiliate Links up to and including 6.2.1.5.
CVE-2022-45840 is characterized as a Missing Authorization vulnerability related to improper access control security levels.
The vendor of the affected software associated with CVE-2022-45840 is Lucian Apostol.