Description
WordPress Plugin WP Affiliate Disclosure is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently perform a variety of the plugin's actions or even take over a website. WordPress Plugin WP Affiliate Disclosure version 1.1.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.4 or latest
References
Related Vulnerabilities
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.4.6)
Joomla! Core 1.5.x Session Hijacking (1.5.0 - 1.5.8)
Drupal Core 8.9.x Multiple Security Bypass Vulnerabilities (8.9.0 - 8.9.18)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21014)