Authentication vulnerability in WordPress & WooCommerce Affiliate Program 8.4.1

The plugin called WordPress & WooCommerce Affiliate Program for WordPress has a security issue in all versions up to 8.4.1. This is because the function that handles user login does not properly check if the user is who they claim to be before giving them access to the site. This means that anyone, even if they are not logged in, can log in as any user, including administrators, as long as they know the administrator’s email.

Detected in:

WordPress & WooCommerce Affiliate Program fixed vulnerable versions: >= * <= 8.4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.