Impact
The vulnerability is a missing authorization flaw in the AnyTrack Affiliate Link Manager WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. This broken access control permits unauthorized users to perform privileged operations such as viewing or modifying affiliate link settings, potentially leading to data exposure or unintended configuration changes. The weakness corresponds to CWE-862 (Missing Authorization).
Affected Systems
AnyTrack’s Affiliate Link Manager plugin for WordPress, versions from the initial release through 1.5.5, is affected. WordPress sites that install any version of the plugin prior to 1.5.6 are susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is through web requests made to the plugin’s administrative endpoints, likely by authenticated users lacking adequate permissions. Exploitation requires that the attacker can send crafted HTTP requests to the plugin’s protected pages; no special preconditions beyond normal WordPress access are documented.
OpenCVE Enrichment