CVE-2023-47232
WordPress vulnerability analysis and mitigation

Overview

CVE-2023-47232 is a Broken Access Control (CSRF) vulnerability in the WP Affiliate Disclosure WordPress plugin by MojofyWP. It affects all versions up to and including 1.2.6, allowing authenticated users with low privileges (Subscriber level) to perform unauthorized actions due to missing authorization or nonce token checks. The vulnerability was reported on May 6, 2023, by researcher Abdi Pranata and published by Patchstack on November 3, 2023; the CVE was formally published on December 21, 2025. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function), manifesting as a missing authorization or nonce token check on a privileged function within the plugin. This allows a low-privileged authenticated user (Subscriber role) to invoke actions that should be restricted to higher-privileged roles, constituting a Broken Access Control issue per OWASP Top 10 A5. The attack vector is network-based, requires low privileges, low attack complexity, and no user interaction. Associated attack patterns include Cross-Site Request Forgery (CAPEC-62) and use of unpublished interfaces (CAPEC-36) (Patchstack).

Impact

Successful exploitation results in a limited availability impact (Low), with no confidentiality or integrity impact according to the CVSS scoring. An attacker with Subscriber-level access could trigger privileged plugin functions without proper authorization, potentially disrupting plugin functionality or site configuration. While the direct impact is constrained, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).

Exploitability

No public exploit code or active in-the-wild exploitation has been specifically reported for CVE-2023-47232. The EPSS score is approximately 0.103%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as a medium-priority issue expected to be exploited in mass-campaign scenarios targeting WordPress plugins broadly (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Affiliate Disclosure plugin version 1.2.6 or earlier using tools like WPScan or Shodan queries targeting WordPress plugin fingerprints.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site (many sites allow open registration).
  3. Identify unprotected endpoint: Locate the plugin function that lacks proper authorization or nonce validation — this could be an admin AJAX action or a settings-update endpoint exposed by the plugin.
  4. Craft malicious request: Send a direct HTTP POST request to the vulnerable endpoint (e.g., wp-admin/admin-ajax.php with the relevant action parameter) without a valid nonce, bypassing the expected access control check.
  5. Achieve unauthorized action: The server processes the request as if it were authorized, allowing the attacker to trigger privileged plugin functionality such as modifying plugin settings or resetting values (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/admin-ajax.php from Subscriber-level user accounts targeting WP Affiliate Disclosure plugin actions, particularly without valid nonce tokens.
  • Logs: Unexpected plugin settings changes recorded in WordPress audit logs or database change logs for the wp_options table related to the wp-affiliate-disclosure plugin.
  • Network: Repeated automated POST requests to WordPress AJAX endpoints from the same IP address or user agent, consistent with mass-exploit scanning behavior.

Mitigation and workarounds

The vendor has released version 1.2.7 of the WP Affiliate Disclosure plugin, which patches this vulnerability. Site administrators should update to version 1.2.7 or later immediately via the WordPress plugin dashboard. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, restricting open user registration or disabling the plugin temporarily are interim mitigations (Patchstack).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of October 30 – November 5, 2023, highlighting it as part of broader WordPress plugin security coverage. Patchstack, the discovering organization, classified it as a medium-priority issue warranting immediate mitigation given the prevalence of mass-exploit campaigns targeting WordPress plugins (Wordfence, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81648CRITICAL10
  • cryptopayment-gateway
NoNoSep 13, 2026
CVE-2026-88793HIGH8.8
  • youram-youtube-embed
NoNoSep 13, 2026
CVE-2026-85129HIGH8.8
  • hoo-companion
NoNoSep 13, 2026
CVE-2026-88802HIGH7.5
  • mobile-dj-manager
NoYesSep 13, 2026
CVE-2026-89050MEDIUM4.3
  • quick-adsense-reloaded
NoYesSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management