CVE-2024-1851: affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkpcreatelist() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating product lists.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1851?
CVE-2024-1851 is considered a high severity vulnerability due to the risk of unauthorized access for authenticated attackers.
How do I fix CVE-2024-1851?
To fix CVE-2024-1851, update the affiliate-toolkit plugin to version 3.5.5 or later.
Who is affected by CVE-2024-1851?
Any WordPress site using the affiliate-toolkit plugin versions up to 3.5.4 is affected by CVE-2024-1851.
What type of vulnerability is CVE-2024-1851?
CVE-2024-1851 is an authorization issue stemming from a missing capability check.
Can an attacker exploit CVE-2024-1851 without an account?
No, an attacker must have an authenticated account at the subscriber level to exploit CVE-2024-1851.