5.4
CVSSv3

CVE-2022-0398

Published: 25/04/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The ThirstyAffiliates Affiliate Link Manager WordPress plugin prior to 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

caseproof thirstyaffiliates affiliate link manager