Description
Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3.
Published: 2026-01-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Patch
AI Analysis

Impact

The AffiliateX plugin for WordPress contains a missing authorization flaw that permits an attacker to bypass the intended access restrictions and use privileged features or view sensitive content. This vulnerability maps to CWE‑862, where insufficient validation of user privileges enables actions beyond the user’s role. The flaw allows unauthorized users to alter plugin settings, read or delete data, and otherwise compromise the website’s configuration and content.

Affected Systems

WordPress sites that have installed the WPCenter AffiliateX plugin from the earliest releases through version 1.3.9.3 are affected. Any site using the plugin at or below this version, regardless of the site’s overall WordPress version, is vulnerable.

Risk and Exploitability

With a CVSS score of 4.3, the vulnerability is considered medium severity, yet the EPSS score of less than 1% indicates that exploitation in the wild is unlikely. The plugin is not listed in the CISA KEV catalog, so no large‑scale public exploits are known. Nevertheless an attacker who can reach the plugin’s administrative interfaces or unauthorized endpoints—especially on a site that grants broader privileges to untrusted users—can exploit the flaw. The primary risk is unauthorized modification of configuration, leakage of sensitive data, and potential disruption of site functionality.

Generated by OpenCVE AI on April 28, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AffiliateX plugin to a version newer than 1.3.9.3
  • If an upgrade cannot be performed immediately, disable the plugin for unauthenticated users and restrict its administration pages to administrator and editor roles only
  • Monitor site logs for unexpected access to plugin endpoints and for unauthorized changes to plugin settings or data

Generated by OpenCVE AI on April 28, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 07 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Tue, 06 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3.
Title WordPress AffiliateX plugin <= 1.3.9.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:38.193Z

Reserved: 2025-12-31T20:12:28.143Z

Link: CVE-2025-69346

cve-icon Vulnrichment

Updated: 2026-01-06T19:47:57.436Z

cve-icon NVD

Status : Deferred

Published: 2026-01-06T17:15:47.110

Modified: 2026-04-27T21:16:24.673

Link: CVE-2025-69346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses