CVE-2024-5285: WP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRF
Published Jul 29, 2024
·Updated
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack
Affected Software
2 affected components
Sye WP Affiliate Platform<6.5.2
Tipsandtricks-hq Wp Affiliate Platform Wordpress<6.5.2
Event History
Jul 29, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5285?
The severity of CVE-2024-5285 is considered moderate due to the potential impact of unauthorized affiliate deletions by exploiting CSRF vulnerability.
2
How do I fix CVE-2024-5285?
To fix CVE-2024-5285, update the WP Affiliate Platform plugin to version 6.5.2 or later.
3
What is the impact of CVE-2024-5285 on users?
CVE-2024-5285 can allow attackers to delete affiliates associated with a logged-in user without their consent.
4
When was CVE-2024-5285 discovered?
CVE-2024-5285 was discovered prior to the release of version 6.5.2 of the WP Affiliate Platform.
5
Which versions of the WP Affiliate Platform are affected by CVE-2024-5285?
All versions of the WP Affiliate Platform prior to 6.5.2 are affected by CVE-2024-5285.