CVE-2024-2298: affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_import_product
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkpimportproduct() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2298?
CVE-2024-2298 has a medium severity rating due to the potential for unauthorized access.
How do I fix CVE-2024-2298?
To fix CVE-2024-2298, update the Affiliate Toolkit plugin to version 3.5.5 or higher, which includes the necessary capability check.
Who is affected by CVE-2024-2298?
CVE-2024-2298 affects all versions of the Affiliate Toolkit plugin for WordPress up to and including version 3.5.4.
What kind of attack can exploit CVE-2024-2298?
Authenticated attackers with subscriber-level permissions can exploit CVE-2024-2298 to gain unauthorized access to features of the plugin.
Is CVE-2024-2298 exploitable without authentication?
No, CVE-2024-2298 requires authentication as it is only exploitable by authenticated users.