Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Fluent Affiliate Pro plugin versions 1.6.4 and earlier. It allows an attacker to bypass standard authentication checks and invoke privileged functions of the plugin that should be restricted to authorized users. The flaw could enable manipulation of affiliate management data or configuration settings without proper authorization.
Affected Systems
All WordPress sites that have the Fluent Affiliate Pro plugin installed at version 1.6.4 or any older release are affected. The plugin is distributed by WP Manage Ninja and the issue exists across all versions up to and including 1.6.4.
Risk and Exploitability
The issue receives a CVSS score of 7.5, classifying it as high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The flaw is unauthenticated and relies on accessing plugin endpoints through the web interface, making it likely that attackers can exploit it remotely without administrative credentials. Successful exploitation would grant the attacker elevated privileges within the WordPress administrative environment for the plugin.
OpenCVE Enrichment