MEDIUM
CVE-2026-57654
CVSS
6.5
Description
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Summary dbcve.org
Broken access control vulnerability in the Affiliates Manager plugin for WordPress allows unauthorized users to access affiliate management functions due to missing or improper authorization checks in versions 2.9.49 and below.
Mitigation
Update Affiliates Manager plugin to the latest version (>2.9.49) and verify that proper role-based access controls are enforced for all affiliate management operations.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.3%
Probability of exploitation in next 30 days
22.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.