CVE-2022-25649 MEDIUM

CVE-2022-25649: WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Multiple Improper Access Control vulnerabilities

Vendor Storeapps
Product Affiliate For WooCommerce (WordPress plugin)
Weakness CWE-264
Published August 5, 2022
Last update April 28, 2026

CVSS base score

5.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Affiliate For WooCommerce plugin for WordPress contains an authorization flaw affecting version 4.7.0 and earlier. An authenticated user with low privileges can read, modify, or delete affiliate data and settings they should not have access to. The vulnerability requires network access and some attack complexity, but no user interaction. Site owners should update immediately to a version newer than 4.7.0.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete affiliate data and plugin settings without proper authorization.

Potential impact on your site

04Site Impact

Affiliate program data could be compromised, modified, or deleted by low-privilege users.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

August 5, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE