Executive brief
The Auto Affiliate Links plugin for WordPress, which helps website owners automatically manage and insert affiliate marketing links, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security restrictions and potentially modify plugin settings or perform actions reserved for administrators. While the impact is considered moderate, it could lead to unauthorized changes in how affiliate links are handled on the site.
Technical details
The Auto Affiliate Links plugin for WordPress (versions up to and including 6.8.8.3) is vulnerable to broken access control due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to bypass security levels and execute functions that should be restricted to higher-privileged users. The vulnerability stems from a failure to properly validate user permissions or implement nonce tokens in specific plugin components. An attacker could potentially manipulate affiliate link configurations or other plugin-specific settings. As of the advisory date, no official patch has been released.
Affected products
- Lucian Apostol Auto Affiliate Links n/a through 6.8.8.3
Timeline
- 2025-12-17: other: Vulnerability reported by researcher Nabil Irawan
- 2026-05-25: advisory: Advisory published by Patchstack
- 2026-05-25: disclosed: CVE-2026-24592 published to NVD