CVE-2023-25973
The Auto Affiliate Links plugin before version 6.3.0.3 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users with elevated privileges into performing unintended operations without their knowledge. An attacker could exploit this flaw to perform actions such as changing account passwords, potentially gaining unauthorized access to administrative accounts. This vulnerability was identified by Rio Darmawan and has been resolved in version 6.3.0.3 and later.
Based on public CVE data (MITRE/NVD).