CVE-2022-36284 MEDIUM

CVE-2022-36284: WordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email change

Vendor Storeapps
Product Affiliate For WooCommerce (WordPress plugin)
Published August 5, 2022
Last update April 28, 2026

CVSS base score

6.4/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payments plugin (free) should be at least installed to get the extra input field on the user profile page.

Explanation of Vulnerability in Simple Terms

02Summary

Affiliate For WooCommerce versions up to 4.7.0 contain a vulnerability allowing authenticated users with low privileges to modify affiliate data and settings. The vulnerability requires network access and high attack complexity, but grants an attacker the ability to alter integrity of affiliate records and potentially access sensitive information. Site administrators should update the plugin immediately.

What an attacker can do

03Attacker Capabilities

Modify affiliate commission data, settings, and access some sensitive information.

Potential impact on your site

04Site Impact

Affiliate commission records and plugin settings can be altered by low-privilege users, potentially causing financial discrepancies and data corruption.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account (e.g., affiliate or subscriber role) on the WordPress site.

Key dates

06Disclosure timeline

August 5, 2022 CVE published
April 28, 2026 Record updated