ZeroHour

CVE-2022-0398

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p24
Published
()
Modified
Description

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

Vendors
caseproof
Products
thirstyaffiliates affiliate link manager
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.