Junglewise Threat Intelligence

CVE-2026-57654: wp.insider Affiliates Manager broken access control

CVE-2026-57654 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Executive brief

Affiliates Manager is a WordPress plugin used to manage affiliate marketing programs. A security flaw in versions 2.9.49 and earlier allows users with affiliate-level accounts to perform actions they should not be authorized to do. This could lead to unauthorized changes to affiliate data or system settings, potentially disrupting marketing operations.

Technical details

A broken access control vulnerability exists in the Affiliates Manager plugin for WordPress (versions <= 2.9.49) due to missing authorization (CWE-862) in certain functions. An attacker authenticated with 'Affiliate' level privileges can exploit this flaw over the network without user interaction. The vulnerability allows these low-privileged users to execute actions that should be restricted to higher-level administrators, primarily impacting data integrity. The issue is resolved in version 2.9.50.

Affected products

  • wp.insider Affiliates Manager <= 2.9.49

Timeline

  • 2026-03-11: disclosed: Reported by Jakub Herman
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Fixed in version 2.9.50

References