Input validation vulnerability in Auto Affiliate Links 6.4.2.4

The Auto Affiliate Links plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery. This means that versions of the plugin up to and including 6.4.2.4 do not properly validate certain functions, such as aalUpdateExcludePosts(). This makes it possible for unauthenticated attackers to change the plugin settings and inject malicious JavaScript, if they are able to fool a site administrator into clicking on a link.

Detected in:

Auto Affiliate Links fixed vulnerable versions: >= * <= 6.4.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.