PT-2026-109699 · Villatheme · Affi – Affiliate Marketing For Woocommerce

CVE-2026-104398

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VillaTheme AFFI – Affiliate Marketing for WooCommerce versions prior to 1.0.11
Description An Object Injection issue exists due to the deserialization of untrusted data. This occurs when the application processes specially crafted serialized data, allowing an attacker to instantiate arbitrary objects and potentially execute unauthorized code.
Recommendations Update VillaTheme AFFI – Affiliate Marketing for WooCommerce to version 1.0.11 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104398

Affected Products

Affi – Affiliate Marketing For Woocommerce