CVE · Medium

CVE-2022-0634 — ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0634 ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.10.5 3.10.5 2022-03-31

CVE-2022-0634

The ThirstyAffiliates plugin before version 3.10.5 contains an authorization vulnerability in the ta_insert_external_image action that permits users with minimal privileges, including those with only Subscriber status, to upload images from external URLs and attach them to affiliate links. The plugin also fails to implement CSRF protections, enabling attackers to manipulate authenticated users into executing these actions through specially crafted requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.