Impact
The flaw is a missing authorization check that allows a user to bypass intended access controls within the Auto Affiliate Links plugin. This results in the potential for unauthorized users to view or modify affiliate link settings, leading to configuration tampering or data leakage. The weakness is identified as CWE-862, reflected in the CVSS score of 5.3.
Affected Systems
All WordPress sites that have the Auto Affiliate Links plugin version 6.8.8.3 or earlier. The affected product is Lucian Apostol's Auto Affiliate Links plugin. Version 6.8.8.3 is the last known vulnerable release; anything newer is considered fixed.
Risk and Exploitability
The CVSS score of 5.3 indicates a low‑to‑medium severity vulnerability. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through the WordPress administrative interface, where a user with sufficient privileges could exploit the broken access control, but the exact prerequisites are not detailed in the description. Overall, the risk is modest, but the potential for unauthorized action warrants timely remediation.
OpenCVE Enrichment