CVE · Medium

CVE-2024-1843 — Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1843 Auto Affiliate Links [wp-auto-affiliate-links] < 6.4.3.1 Missing Authorization Medium 4.3 < 6.4.3.1 6.4.3.1 2024-03-11

CVE-2024-1843

The Auto Affiliate Links plugin before version 6.4.3.1 contains a broken access control vulnerability that allows unauthorized users to perform actions restricted to higher-privileged roles due to missing authorization and authentication checks. Researcher Lucio Sá identified the flaw, which stems from the absence of proper nonce token validation in one of the plugin's functions. Users should upgrade to version 6.4.3.1 or later to resolve this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.