PT-2026-109699 · Villatheme · Affi – Affiliate Marketing For Woocommerce
CVE-2026-104398
·
Published
2026-10-10
·
Updated
2026-10-10
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VillaTheme AFFI – Affiliate Marketing for WooCommerce versions prior to 1.0.11
Description
An Object Injection issue exists due to the deserialization of untrusted data. This occurs when the application processes specially crafted serialized data, allowing an attacker to instantiate arbitrary objects and potentially execute unauthorized code.
Recommendations
Update VillaTheme AFFI – Affiliate Marketing for WooCommerce to version 1.0.11 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Affi – Affiliate Marketing For Woocommerce