What the vulnerability does
01Description
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating product lists.
Explanation of Vulnerability in Simple Terms
02Summary
The Affiliate Toolkit plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to read, modify, or delete data they should not have access to. An attacker with a basic user account can exploit this to access sensitive affiliate or product information. The vulnerability affects all versions up to 3.5.4.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete affiliate data and product information without proper authorization.
Potential impact on your site
04Site Impact
Affiliate data, product listings, and sensitive configuration may be exposed or altered by low-privilege users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
March 8, 2024
CVE published
April 8, 2026
Record updated