WordPress · Villatheme Affi · CVE-2026-102390
**Name of the Vulnerable Software and Affected Versions**
VillaTheme AFFI – Affiliate Marketing for WooCommerce versions prior to 1.1.0
**Description**
Missing authorization in the `affi-affiliate-marketing-for-woo` component allows for the exploitation of incorrectly configured access control security levels, leading to broken access control.
**Recommendations**
Update VillaTheme AFFI – Affiliate Marketing for WooCommerce to version 1.1.0 or later.