What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.
Explanation of Vulnerability in Simple Terms
Affiliates Manager through version 2.9.30 exposes sensitive information without proper access controls. An unauthenticated attacker can read data that should be restricted, such as affiliate details or configuration information. The vulnerability requires no special setup and can be exploited remotely over the network. Site administrators should update to a version newer than 2.9.30 immediately.
What an attacker can do
Read sensitive affiliate or configuration data without authentication.
Potential impact on your site
Affiliate data, earnings, or site configuration may be exposed to the public.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities