Loading HuntDB...

GHSA-4gvj-wfph-8c6j

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.

Related CVEs

Key Information

GHSA ID
GHSA-4gvj-wfph-8c6j
Published
October 1, 2024 9:30 AM
Last Modified
October 1, 2024 9:30 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.