What the vulnerability does
01Description
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.
Explanation of Vulnerability in Simple Terms
The Affiliate For WooCommerce plugin for WordPress contains an authorization flaw affecting version 4.7.0 and earlier. An authenticated user with low privileges can read, modify, or delete affiliate data and settings they should not have access to. The vulnerability requires network access and some attack complexity, but no user interaction. Site owners should update immediately to a version newer than 4.7.0.
What an attacker can do
Read, modify, or delete affiliate data and plugin settings without proper authorization.
Potential impact on your site
Affiliate program data could be compromised, modified, or deleted by low-privilege users.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities