Executive brief
The AliNext plugin for WordPress, which facilitates AliExpress dropshipping, contains a security flaw that fails to properly verify user permissions. This allows logged-in users with low-level access, such as subscribers, to perform actions or access data they should not be authorized to see. This could lead to the exposure of sensitive business information or unauthorized changes to the dropshipping configuration.
Technical details
A missing authorization vulnerability (CWE-862) exists in the ali2woo AliNext (Lite) plugin for WordPress in versions up to and including 3.3.5. The flaw stems from insufficient access control checks on certain functions, which allows an authenticated attacker with 'Subscriber' level permissions to bypass intended security restrictions. By exploiting this, an attacker can perform actions or access information that should be restricted to higher-privileged users. The issue is resolved in version 3.3.7.
Affected products
- ali2woo AliNext (AliExpress Dropshipping with AliNext Lite) up to 3.3.5
Timeline
- 2024-02-17: other: Vulnerability reported by researcher Majed Refaea
- 2024-06-17: disclosed: CVE published
- 2024-06-20: advisory: Patchstack advisory published
- 3.3.7: patched