Impact
The vulnerability allows an unauthenticated attacker to elevate privileges within the Affiliate Pro plugin, enabling them to perform actions reserved for administrators or other privileged users. The flaw is a classic Example of improper privilege assignment (CWE-266) which could lead to unauthorized configuration changes, data exposure, or further exploitation of the host system.
Affected Systems
The affected product is Affiliate Pro – Affiliate Program for WooCommerce & WordPress by RedefiningTheWeb. Versions 8.9.1 and earlier are vulnerable. Users operating these plugin versions on a WordPress site are at risk.
Risk and Exploitability
The CVSS score of 9.8 highlights the severity of this flaw. With no authentication required, an attacker can exploit it remotely without any prior access, making it highly dangerous. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the high severity and lack of prerequisite conditions indicate a meaningful risk for exposed WordPress sites running the vulnerable plugin.
OpenCVE Enrichment