Description
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27253 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products. |
References
History
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | affiliate-toolkit – WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_import_product |
Wed, 15 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Servit
Servit affiliate-toolkit |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:servit:affiliate-toolkit:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Servit
Servit affiliate-toolkit |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:51:25.255Z
Reserved: 2024-03-07T18:55:40.430Z
Link: CVE-2024-2298
Updated: 2024-08-01T19:11:52.483Z
Status : Modified
Published: 2024-03-08T07:15:06.457
Modified: 2026-04-08T18:21:03.040
Link: CVE-2024-2298
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD