6.5
CVSSv3

CVE-2024-12336

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.0004 | KEV: Not Included
Published: 15/03/2025 Updated: 28/03/2025

Vulnerability Summary

Authenticated Data Exposure Vulnerability in WC Affiliate Plugin for WordPress

The WC Affiliate plugin for WordPress has a security vulnerability in its 'export_all_data' function across all versions up to and including 2.5.3. This issue allows authenticated users with Subscriber-level access or higher to improperly access and expose sensitive affiliate data, which may include personally identifiable information. The vulnerability stems from a missing capability check in the function, enabling unauthorized data access for lower-privileged users.

Vulnerable Product Search on Vulmon Subscribe to Product

codexpert wc affiliate – a complete woocommerce affiliate plugin

codexpert wc affiliate