• katy8439

    (@katy8439)


    I have been notified by my security plugin that Auto Affiliate Links is vulnerable to “WordPress Auto Affiliate Links Plugin <= 6.4.2.4 is vulnerable to Cross Site Request Forgery (CSRF)” (link) which occurred after that latest update

    Is there an ETA on a patch for this?

    Thanks

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Lucian Apostol

    (@thedark)

    Hello.

    Thank you for reporting this.

    This issue was fixed in version 6.4.1, you can see the update in the readme.txt file.

    It seems that the report was not updated on patchstack. I will contact them so they can mark it as resolved.

    Plugin Author Lucian Apostol

    (@thedark)

    It seems that there was a confusion and the issue was not fixed. I will provide a fix as soon as possible.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Security Warning CSRF Vulnerability’ is closed to new replies.