CVE-2023-4600: Medium severity wordpress affiliate tools vulnerability
The AffiliateWP for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'affwpactivateaddonspageplugin' function called via an AJAX action in versions up to, and including, 2.14.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to activate arbitrary plugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4600?
The severity of CVE-2023-4600 is categorized as medium due to unauthorized data modification risks.
How do I fix CVE-2023-4600?
To fix CVE-2023-4600, update the AffiliateWP plugin to version 2.14.1 or later.
Who is affected by CVE-2023-4600?
CVE-2023-4600 affects users of AffiliateWP for WordPress versions up to and including 2.14.0.
What kind of attacks are possible with CVE-2023-4600?
CVE-2023-4600 allows authenticated attackers to modify data without proper permission checks.
Is it safe to use earlier versions of AffiliateWP after CVE-2023-4600 is disclosed?
No, it is unsafe to use earlier versions of AffiliateWP after CVE-2023-4600 is disclosed due to the exploitation risks.