Executive brief
AnyTrack Affiliate Link Manager is a WordPress plugin used to manage and track affiliate marketing links. A security flaw in the plugin allows unauthorized individuals to bypass access controls, potentially allowing them to modify settings or perform actions intended only for site administrators. This could lead to the manipulation of affiliate links or tracking data, impacting marketing revenue and data integrity.
Technical details
A missing authorization vulnerability (CWE-862) exists in the AnyTrack Affiliate Link Manager plugin for WordPress through version 1.5.5. The flaw stems from a failure to implement proper permission checks or nonce validation on sensitive functions, allowing an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. An attacker can exploit this by sending crafted network requests to the vulnerable component. At the time of reporting, no official patch is available, and the vulnerability affects all versions up to and including 1.5.5.
Affected products
- AnyTrack AnyTrack Affiliate Link Manager <= 1.5.5
Timeline
- 2026-01-31: other: Vulnerability reported by researcher Nabil Irawan
- 2026-03-02: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD