CVE · Medium

CVE-2024-5864 — Easy Affiliate Links [easy-affiliate-links] < 3.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5864 Easy Affiliate Links [easy-affiliate-links] < 3.7.4 Missing Authorization Medium 4.3 < 3.7.4 3.7.4 2024-06-27

CVE-2024-5864

A security flaw exists in Easy Affiliate Links plugin for WordPress, affecting versions prior to 3.7.4, where an insufficient capability check allows users with a minimum of Subscriber permissions to execute the eafl_reset_settings AJAX action without authorization, enabling them to modify plugin settings. This vulnerability can be exploited by authenticated attackers to reset the plugin's configuration.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.