CVE-2026-32558: WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPressto a version that resolves this vulnerability.Fixed in 8.9.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need an existing WordPress account or other prior privileges to exploit it.
Which installations are affected?
WordPress sites using the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin version 8.9.1 or earlier are affected.
What is the potential impact?
Successful exploitation can result in privilege escalation. The supplied CVSS vector indicates network-reachable exploitation with no privileges or user interaction required and high impact to confidentiality, integrity, and availability.