MEDIUM

CVE-2026-57654

2026-06-26 CVSS v3.1
CVSS
6.5

Description

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

Summary dbcve.org

Broken access control vulnerability in the Affiliates Manager plugin for WordPress allows unauthorized users to access affiliate management functions due to missing or improper authorization checks in versions 2.9.49 and below.

Mitigation

Update Affiliates Manager plugin to the latest version (>2.9.49) and verify that proper role-based access controls are enforced for all affiliate management operations.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.3%
Probability of exploitation in next 30 days
22.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE