Impact
The Affilia plugin allows authenticated users with subscriber level or higher to approve, reject, credit commissions to affiliate wallets, delete referral records and alter banner options. Because the plugin does not verify user authorization properly (CWE‑862), an attacker can manipulate affiliate finances and commissions, effectively performing financial fraud. No remote code execution or network‑wide impact is described, but the consequences include unauthorized monetary transactions and reputational damage to the site owner.
Affected Systems
All WordPress sites using the Affilia – Affiliate Program & Referral Tracking plugin up to and including version 3.3.3 are affected. The vulnerability exists regardless of the specific WordPress version, as it is tied solely to the plugin code.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of less than 1% suggests low exploitation probability in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attacks require that the attacker has an authenticated subscriber or higher role; the browser‑exposed nonce exposes a trivially bypassable authentication check. Consequently, the risk is moderate but the impact is significant if the flaw is leveraged to manipulate affiliate financial records.
OpenCVE Enrichment