vulnerability
WordPress Plugin: thirstyaffiliates: CVE-2022-0398: Missing Authorization
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:M/Au:S/C:P/I:P/A:N) | Apr 10, 2022 | May 15, 2025 | May 15, 2025 |
Severity
5
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:N)
Published
Apr 10, 2022
Added
May 15, 2025
Modified
May 15, 2025
Description
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and Cross-Site Request Forgery checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website
Solution
thirstyaffiliates-plugin-cve-2022-0398

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.