The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 | |
CPEs | cpe:2.3:a:redefiningtheweb:affiliate_pro:*:*:*:*:*:wordpress:*:* |
Tue, 01 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redefiningtheweb
Redefiningtheweb affiliate Pro |
|
CPEs | cpe:2.3:a:redefiningtheweb:affiliate_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Redefiningtheweb
Redefiningtheweb affiliate Pro |
|
Metrics |
ssvc
|
Tue, 01 Oct 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email. | |
Title | WordPress & WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass to Account Takeover and Privilege Escalation | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-01T08:30:19.607Z
Updated: 2024-10-01T14:27:13.343Z
Reserved: 2024-09-27T15:41:11.548Z
Link: CVE-2024-9289
Vulnrichment
Updated: 2024-10-01T14:27:06.720Z
NVD
Status : Analyzed
Published: 2024-10-01T09:15:09.320
Modified: 2024-10-07T18:25:21.380
Link: CVE-2024-9289
Redhat
No data.