CVE-2026-102390: WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/affi-affiliate-marketing-for-wooto a version that resolves this vulnerability.Fixed in 1.0.10
Event History
Frequently Asked Questions
Which installations are affected?
The issue affects VillaTheme AFFI – Affiliate Marketing for WooCommerce versions through 1.0.9. The provided data does not identify a fixed version.
Does exploitation require an authenticated account or user interaction?
No. The vector indicates network-based exploitation with no privileges required and no user interaction required.
What is the expected impact of successful exploitation?
The reported impact is limited to integrity, with no stated confidentiality or availability impact. The severity vector rates it 5.3 (medium).