
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-47232 is a Broken Access Control (CSRF) vulnerability in the WP Affiliate Disclosure WordPress plugin by MojofyWP. It affects all versions up to and including 1.2.6, allowing authenticated users with low privileges (Subscriber level) to perform unauthorized actions due to missing authorization or nonce token checks. The vulnerability was reported on May 6, 2023, by researcher Abdi Pranata and published by Patchstack on November 3, 2023; the CVE was formally published on December 21, 2025. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, Red Hat CVE).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function), manifesting as a missing authorization or nonce token check on a privileged function within the plugin. This allows a low-privileged authenticated user (Subscriber role) to invoke actions that should be restricted to higher-privileged roles, constituting a Broken Access Control issue per OWASP Top 10 A5. The attack vector is network-based, requires low privileges, low attack complexity, and no user interaction. Associated attack patterns include Cross-Site Request Forgery (CAPEC-62) and use of unpublished interfaces (CAPEC-36) (Patchstack).
Successful exploitation results in a limited availability impact (Low), with no confidentiality or integrity impact according to the CVSS scoring. An attacker with Subscriber-level access could trigger privileged plugin functions without proper authorization, potentially disrupting plugin functionality or site configuration. While the direct impact is constrained, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).
No public exploit code or active in-the-wild exploitation has been specifically reported for CVE-2023-47232. The EPSS score is approximately 0.103%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as a medium-priority issue expected to be exploited in mass-campaign scenarios targeting WordPress plugins broadly (Patchstack).
wp-admin/admin-ajax.php with the relevant action parameter) without a valid nonce, bypassing the expected access control check.wp-admin/admin-ajax.php from Subscriber-level user accounts targeting WP Affiliate Disclosure plugin actions, particularly without valid nonce tokens.wp_options table related to the wp-affiliate-disclosure plugin.The vendor has released version 1.2.7 of the WP Affiliate Disclosure plugin, which patches this vulnerability. Site administrators should update to version 1.2.7 or later immediately via the WordPress plugin dashboard. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, restricting open user registration or disabling the plugin temporarily are interim mitigations (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of October 30 – November 5, 2023, highlighting it as part of broader WordPress plugin security coverage. Patchstack, the discovering organization, classified it as a medium-priority issue warranting immediate mitigation given the prevalence of mass-exploit campaigns targeting WordPress plugins (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."