CVE · Medium

CVE-2023-25973 — Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-25973 Auto Affiliate Links [wp-auto-affiliate-links] < 6.3.0.3 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.3.0.3 6.3.0.3 2023-02-22

CVE-2023-25973

The Auto Affiliate Links plugin before version 6.3.0.3 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users with elevated privileges into performing unintended operations without their knowledge. An attacker could exploit this flaw to perform actions such as changing account passwords, potentially gaining unauthorized access to administrative accounts. This vulnerability was identified by Rio Darmawan and has been resolved in version 6.3.0.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.