CVE Database /
CVE-2022-0634
CVE · Medium
CVE-2022-0634 — ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0634
|
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.10.5 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 3.10.5
|
3.10.5 |
2022-03-31 |
—
|
CVE-2022-0634
The ThirstyAffiliates plugin before version 3.10.5 contains an authorization vulnerability in the ta_insert_external_image action that permits users with minimal privileges, including those with only Subscriber status, to upload images from external URLs and attach them to affiliate links. The plugin also fails to implement CSRF protections, enabling attackers to manipulate authenticated users into executing these actions through specially crafted requests.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings