First published: Wed Mar 13 2024(Updated: )
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to posts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Auto Affiliate Links | <6.4.3.1 | |
WordPress Auto Affiliate Links | <=6.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1843 is considered a high severity vulnerability due to the potential for unauthorized data modification.
To fix CVE-2024-1843, update the Auto Affiliate Links plugin to version 6.4.3.1 or later.
Authenticated users with subscriber access or higher on WordPress sites using the affected versions of the Auto Affiliate Links plugin are at risk from CVE-2024-1843.
CVE-2024-1843 allows authenticated attackers to modify data, potentially compromising the integrity of the site's content.
All versions of the Auto Affiliate Links plugin up to and including 6.4.3 are impacted by CVE-2024-1843.