PatchSiren

AnyTrack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM AnyTrack CVE published 2026-04-08

CVE-2026-39715

A Missing Authorization vulnerability was found in AnyTrack Affiliate Link Manager, allowing for Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability affects AnyTrack Affiliate Link Manager versions from n/a through <= 1.5.5. This MEDIUM severity issue has a CVSS score of 5.3. Users should review and update the plugin to a version beyond 1.5.5 if available.