Description
WordPress Plugin YITH WooCommerce Affiliates is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Affiliates version 1.6.3 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Multisite Plugin Manager Multiple Cross-Site Scripting Vulnerabilities (3.1.1)
WordPress Plugin Advanced Contact form 7 DB Information Disclosure (1.1.0)
WordPress Plugin Ocean Extra Cross-Site Request Forgery (1.6.5)
WordPress Plugin 10Web Map Builder for Google Maps SQL Injection (1.0.72)