Description
WordPress Plugin YITH WooCommerce Affiliates is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Affiliates version 1.6.3 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WordPress File Upload Arbitrary File Upload (3.4.0)
Ruby Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-10933)
WordPress Plugin Doneren met Mollie Information Disclosure (2.8.4)
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268)
WordPress Plugin Podcast Channels Cross-Site Scripting (0.20)