Vulnerabilities > CVE-2022-0398 - Missing Authorization vulnerability in Caseproof Thirstyaffiliates Affiliate Link Manager

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
caseproof
CWE-862

Summary

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

Vulnerable Configurations

Part Description Count
Application
Caseproof
71

Common Weakness Enumeration (CWE)