What the vulnerability does
01Description
Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.
Explanation of Vulnerability in Simple Terms
02Summary
Affiliate For WooCommerce versions up to 4.7.0 contain a vulnerability allowing authenticated users with low privileges to modify affiliate data and settings. The vulnerability requires network access and high attack complexity, but grants an attacker the ability to alter integrity of affiliate records and potentially access sensitive information. Site administrators should update the plugin immediately.
What an attacker can do
03Attacker Capabilities
Modify affiliate commission data, settings, and access some sensitive information.
Potential impact on your site
04Site Impact
Affiliate commission records and plugin settings can be altered by low-privilege users, potentially causing financial discrepancies and data corruption.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account (e.g., affiliate or subscriber role) on the WordPress site.
Key dates
06Disclosure timeline
August 5, 2022
CVE published
April 28, 2026
Record updated