CVE-2026-104398: WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.10 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AFFI – Affiliate Marketing for WooCommerce (affi-affiliate-marketing-for-woo)to a version that resolves this vulnerability.Fixed in 1.0.11
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The reported CVSS vector indicates it can be exploited remotely over the network with low attack complexity, without authentication or user interaction.
Which installations are affected?
AFFI – Affiliate Marketing for WooCommerce versions through 1.0.10 are affected. The available data does not identify any unaffected fixed version.
What is the potential impact?
The vulnerability is rated critical with high potential impact to confidentiality, integrity, and availability. It involves deserialization of untrusted data that can lead to PHP object injection.