What the vulnerability does
01Description
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Explanation of Vulnerability in Simple Terms
Affiliate Pro for WooCommerce & WordPress versions up to 8.9.1 contain a privilege assignment flaw that allows unauthenticated attackers to gain unauthorized access to sensitive functionality. An attacker can read, modify, or delete data without any credentials or user interaction. This affects all installations running the vulnerable version.
What an attacker can do
Read, modify, or delete site data and user information without logging in.
Potential impact on your site
Attackers can compromise user accounts, steal affiliate data, modify commissions, or take the site offline.
Conditions required to exploit
None. The attacker needs only network access to the site.
Key dates
External resources
Related vulnerabilities