Description
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Published: 2026-06-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress Affiliates Manager plugin through version 2.9.49 contains a broken access control flaw. The plugin fails to enforce proper permission checks on privileged operations, allowing an attacker who can send crafted requests to the plugin’s endpoints to modify or create affiliate records. This can compromise data confidentiality and integrity, and in some configurations could elevate the attacker's privileges to administrative levels within the WordPress installation.

Affected Systems

Any WordPress website that has installed the Affiliates Manager plugin (wp.insider: Affiliates Manager) version 2.9.49 or earlier is affected. This includes sites using the plugin directly, or any installations that have inherited the plugin through a theme or another plugin that bundles it.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating a medium severity risk. The EPSS score is not available, so the likelihood of exploitation is uncertain; however, the flaw is not included in the CISA KEV catalog. Attackers can potentially exploit the issue remotely via the web interface, provided they can craft a request to the vulnerable plugin’s endpoints. The lack of known public exploits suggests that exploitation would require custom development, but the medium severity score warrants prompt attention.

Generated by OpenCVE AI on June 26, 2026 at 18:04 UTC.

Remediation

Vendor Solution

Update the WordPress Affiliates Manager Plugin to the latest available version (at least 2.9.50).


OpenCVE Recommended Actions

  • Update the WordPress Affiliates Manager plugin to version 2.9.50 or later.
  • Remove or disable any instances of the plugin that remain at v2.9.49 or older.
  • Review and tighten role permissions within WordPress, ensuring that only users requiring affiliate management capabilities can access related functionality.

Generated by OpenCVE AI on June 26, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp.insider
Wp.insider affiliates Manager
Vendors & Products Wordpress
Wordpress wordpress
Wp.insider
Wp.insider affiliates Manager

Fri, 26 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Description Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Title WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Wordpress Wordpress
Wp.insider Affiliates Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-26T14:53:24.234Z

Reserved: 2026-06-25T08:03:24.124Z

Link: CVE-2026-57654

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T21:15:03Z

Weaknesses