Impact
The AffiliateX plugin for WordPress contains a missing authorization flaw that permits an attacker to bypass the intended access restrictions and use privileged features or view sensitive content. This vulnerability maps to CWE‑862, where insufficient validation of user privileges enables actions beyond the user’s role. The flaw allows unauthorized users to alter plugin settings, read or delete data, and otherwise compromise the website’s configuration and content.
Affected Systems
WordPress sites that have installed the WPCenter AffiliateX plugin from the earliest releases through version 1.3.9.3 are affected. Any site using the plugin at or below this version, regardless of the site’s overall WordPress version, is vulnerable.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered medium severity, yet the EPSS score of less than 1% indicates that exploitation in the wild is unlikely. The plugin is not listed in the CISA KEV catalog, so no large‑scale public exploits are known. Nevertheless an attacker who can reach the plugin’s administrative interfaces or unauthorized endpoints—especially on a site that grants broader privileges to untrusted users—can exploit the flaw. The primary risk is unauthorized modification of configuration, leakage of sensitive data, and potential disruption of site functionality.
OpenCVE Enrichment