CVE-2026-42721: WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability
Published Oct 7, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
Affected Software
1 affected component
SERVIT Software Solutions affiliate-toolkit<=3.9.1
Event History
Oct 7, 2026
CVE Published
via MITRE·09:56 AM
Data Sourced
via MITRE·09:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Installations using the SERVIT Software Solutions affiliate-toolkit plugin are affected through version 3.9.1. The available data does not identify a fixed release.
2
What access does an attacker need?
Exploitation is network-reachable and has low attack complexity, but requires high privileges. Successful exploitation can expose confidential information and has a low availability impact; integrity impact is not indicated.