CVE-2024-9289

CRITICAL

WordPress WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass

Title source: llm
STIX 2.1

Description

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.

Scores

CVSS v3 9.8
EPSS 0.0056
EPSS Percentile 41.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-288
Status published
Products (2)
redefiningtheweb/affiliate_pro < 8.5.0
RedefiningTheWeb/WordPress & WooCommerce Affiliate Program < 8.4.1
Published Oct 01, 2024
Tracked Since Feb 18, 2026