Authenticated Data Exposure Vulnerability in WC Affiliate Plugin for WordPress
The WC Affiliate plugin for WordPress has a security vulnerability in its 'export_all_data' function across all versions up to and including 2.5.3. This issue allows authenticated users with Subscriber-level access or higher to improperly access and expose sensitive affiliate data, which may include personally identifiable information. The vulnerability stems from a missing capability check in the function, enabling unauthorized data access for lower-privileged users.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
codexpert wc affiliate – a complete woocommerce affiliate plugin |
||
codexpert wc affiliate |