Executive brief
Affiliates Manager is a WordPress plugin used to manage affiliate marketing programs. A security flaw in versions 2.9.49 and earlier allows users with affiliate-level accounts to perform actions they should not be authorized to do. This could lead to unauthorized changes to affiliate data or system settings, potentially disrupting marketing operations.
Technical details
A broken access control vulnerability exists in the Affiliates Manager plugin for WordPress (versions <= 2.9.49) due to missing authorization (CWE-862) in certain functions. An attacker authenticated with 'Affiliate' level privileges can exploit this flaw over the network without user interaction. The vulnerability allows these low-privileged users to execute actions that should be restricted to higher-level administrators, primarily impacting data integrity. The issue is resolved in version 2.9.50.
Affected products
- wp.insider Affiliates Manager <= 2.9.49
Timeline
- 2026-03-11: disclosed: Reported by Jakub Herman
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Fixed in version 2.9.50