Junglewise Threat Intelligence

CVE-2025-14361: AA-Team Woocommerce Envato Affiliates missing authorization in settings

CVE-2025-14361 · Severity: high · CVSS 7.1 · Published 2026-05-26

Executive brief

The AA-Team Woocommerce Envato Affiliates plugin for WordPress, which helps store owners manage affiliate products, contains a security flaw that allows unauthorized users to change plugin settings. An attacker with a basic user account could modify how the plugin operates, potentially disrupting affiliate tracking or altering store configurations. This could lead to operational issues or financial discrepancies in affiliate payouts.

Technical details

A missing authorization vulnerability (CWE-862) exists in the AA-Team Woocommerce Envato Affiliates plugin through version 1.2.1. The flaw allows an authenticated attacker with low-level privileges (such as a Subscriber) to access and modify plugin settings that should be restricted to administrators. This occurs because the affected functionality does not properly enforce Access Control Lists (ACLs). An attacker can exploit this over the network without user interaction to change configuration parameters, impacting the integrity of the plugin's operations. As of the advisory date, no official patch is available.

Affected products

  • AA-Team Woocommerce Envato Affiliates <= 1.2.1

Timeline

  • 2025-08-13: other: Reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-05-26: advisory: Published by Patchstack and NVD

References