The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.
History

Mon, 07 Oct 2024 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CPEs cpe:2.3:a:redefiningtheweb:affiliate_pro:*:*:*:*:*:wordpress:*:*

Tue, 01 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redefiningtheweb
Redefiningtheweb affiliate Pro
CPEs cpe:2.3:a:redefiningtheweb:affiliate_pro:*:*:*:*:*:*:*:*
Vendors & Products Redefiningtheweb
Redefiningtheweb affiliate Pro
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 08:45:00 +0000

Type Values Removed Values Added
Description The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.
Title WordPress & WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass to Account Takeover and Privilege Escalation
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-01T08:30:19.607Z

Updated: 2024-10-01T14:27:13.343Z

Reserved: 2024-09-27T15:41:11.548Z

Link: CVE-2024-9289

cve-icon Vulnrichment

Updated: 2024-10-01T14:27:06.720Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-01T09:15:09.320

Modified: 2024-10-07T18:25:21.380

Link: CVE-2024-9289

cve-icon Redhat

No data.