Skip to content
eastbaycyber

CVE-2026-104398: PHP Object Injection in AFFI WooCommerce Plugin

CVSS · Critical
9.8
In CISA KEV
No
Published
Oct 10
CVE explainers 9 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-10
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-104398 is a CVSS 9.8 PHP object-injection vulnerability in VillaTheme’s AFFI plugin through version 1.0.10. - Affected WordPress administrators should upgrade to the latest release, verify the fixed version, or disable the plugin temporarily. - No verified public PoC or confirmed exploitation in the wild was identified; treat the issue as critical because the CVSS score is 9.8.

Vulnerability at a Glance

CVE-2026-104398 affects the WordPress AFFI – Affiliate Marketing for WooCommerce plugin, distributed by VillaTheme under the plugin slug affi-affiliate-marketing-for-woo. The NVD description classifies the issue as deserialization of untrusted data that permits PHP object injection.

Field Details
CVE ID CVE-2026-104398
CVSS score 9.8, Critical
CVSS vector Not supplied in the retrieved NVD response
Attack vector Unknown from the available record
Authentication required Unknown from the available record
Affected versions Through and including 1.0.10
Patch available Yes, according to Patchstack; exact fixed version not exposed in retrieved advisory content
CISA KEV status Not listed
Confirmed exploitation Not identified in the reviewed sources
Verified public PoC Not identified in the reviewed sources

The score warrants urgent triage, but several exploitability details remain unavailable. Defenders should not assume from the 9.8 score alone that the vulnerable path is unauthenticated, remotely reachable, or exploitable through every WordPress installation.

The affected-version boundary is clearer than the remediation boundary: versions through 1.0.10 are identified as affected, while the precise fixed release was not available in the retrieved Patchstack content. Do not treat “latest installed” as proof of remediation without checking the installed version and the vendor’s current release information.

What Is This Vulnerability?

CVE-2026-104398 is a CWE-502: Deserialization of Untrusted Data vulnerability. In a vulnerable PHP application, attacker-controlled serialized data can be converted into PHP objects. If the application accepts that data without adequate validation and the runtime contains usable magic methods or gadget chains, object construction can trigger unintended behavior.

The available record does not identify the vulnerable PHP function, request parameter, REST route, AJAX action, cookie, or administrative workflow. It also does not publish a confirmed gadget chain. The precise exploitation path and final impact therefore cannot be established from the available primary material. Potential outcomes for PHP object-injection flaws can include unauthorized application actions, file manipulation, or remote code execution when the surrounding code and dependencies provide a suitable chain, but these outcomes should not be presented as confirmed for this CVE.

The practical risk is higher on WordPress sites where the plugin processes data from untrusted requests or where a compromised authenticated account can reach plugin functionality. Because the endpoint and authentication requirements are missing, defenders should review both public-facing traffic and authenticated WordPress activity rather than limiting the investigation to administrator logins.

AnalystImpact · assess the risk

Who Is Affected?

The affected product is VillaTheme’s AFFI – Affiliate Marketing for WooCommerce plugin for WordPress. The documented affected range is:

  • Product: AFFI – Affiliate Marketing for WooCommerce
  • Plugin slug: affi-affiliate-marketing-for-woo
  • Affected range: through and including 1.0.10
  • Lower bound: reported as n/a in the NVD record
  • Affected release explicitly identified by advisory title: 1.0.10 and earlier

Any WordPress installation with version 1.0.10 or an earlier version should be considered affected until the plugin is upgraded to a vendor-confirmed fixed release. This includes production stores, staging systems, development sites, and dormant WordPress instances that remain reachable from the internet. A site does not need to use every AFFI feature to be relevant; the plugin may still register code, routes, hooks, or handlers during normal WordPress execution.

The precise fixed version is not exposed in the retrieved Patchstack advisory material. Patchstack indicates that mitigation or a fix is available, but the available evidence does not support naming a specific release number. Confirm the current version through the WordPress update system, VillaTheme’s release information, or the official plugin distribution channel before closing the vulnerability as remediated.

CVSS Score Breakdown

The CVSS base score is 9.8, rated Critical. However, the retrieved NVD response supplied the score without a CVSS vector string. Without that vector, the individual metric values cannot be reliably stated. The available data does not establish the attack vector, attack complexity, privileges required, user interaction, scope, or the confidentiality, integrity, and availability impact components.

This limitation matters operationally. A score of 9.8 commonly indicates a highly damaging and readily exploitable combination of metrics, but reconstructing those metrics from the numeric score would be speculation. Security teams should record the score as critical while separately marking the exploit prerequisites as unknown. Asset owners should confirm the vector from a later NVD update or a complete vendor advisory if one becomes available.

The score should drive prioritization, not unsupported assumptions about reachability. Internet-facing WordPress stores and sites handling payment, customer, or affiliate data deserve immediate attention. Internal or access-restricted sites still require remediation because WordPress credentials, vulnerable plugins, and application integrations can provide paths into otherwise protected environments.

Analyst’s Take: Start with version inventory and exposure, not exploitability assumptions. The 9.8 score warrants urgent action, but the missing CVSS vector, vulnerable route, and fixed version mean administrators must verify both the affected installation and the vendor-confirmed remediation state.

Exploitation Status

CVE-2026-104398 was not listed in the CISA Known Exploited Vulnerabilities catalog at the time of the referenced check. No confirmed in-the-wild exploitation was identified in the reviewed NVD, Patchstack, CISA, or contextual vulnerability-index material. The reviewed material also did not identify a verified public proof-of-concept repository or exploit implementation.

The absence of a KEV listing or public PoC is not evidence that exploitation is impossible. It means only that confirmed exploitation was not established by the sources reviewed. PHP object-injection vulnerabilities can become more actionable when researchers identify the relevant input path and gadget chain, so organizations should not defer patching while waiting for exploitation evidence.

Treat the status as not confirmed, not as safe. If an affected installation was publicly reachable, investigate for suspicious requests, unexpected file changes, new WordPress users, altered scheduled tasks, plugin modifications, and outbound connections from the web server. Where the plugin handled sensitive commerce workflows, preserve relevant logs before making destructive changes. See this log management glossary for background on collecting and retaining the records needed for investigation.

ResponderRunbook · act now

How to Detect It

Start by building an inventory of the plugin across all WordPress environments. WordPress administrators can check the installed version with WP-CLI:

wp plugin get affi-affiliate-marketing-for-woo \
  --field=version \
  --path=/var/www/html

A result of 1.0.10 or lower should be treated as vulnerable. The command does not prove that the installed code matches the official package, so incident responders should also compare plugin files with a trusted package where feasible and check for unexpected modifications.

The vulnerable endpoint and parameter are not disclosed in the available records, so there is no validated network signature for this CVE. Use layered, heuristic searches rather than a claimed CVE-specific rule. Review web access logs for requests containing serialized PHP markers or requests targeting plugin-related paths:

zgrep -Eai \
  '(^|[^A-Za-z0-9_])(O:[0-9]+:"|a:[0-9]+:\{|s:[0-9]+:")' \
  /var/log/nginx/access.log* /var/log/apache2/access.log*

The pattern can produce false positives because serialized data may appear in legitimate application traffic. Correlate matches with the request URI, source address, response status, authenticated WordPress user, user-agent, and subsequent server activity. Also search for plugin paths and suspicious PHP errors:

zgrep -Eai \
  'affi-affiliate-marketing-for-woo|unserialize|__wakeup|__destruct|fatal error|parse error' \
  /var/log/nginx/access.log* /var/log/apache2/error.log* \
  /var/log/php*-fpm.log*

These strings are investigative indicators, not proof of exploitation. PHP application logs may not record request bodies, and reverse proxies may normalize or omit parameters. If centralized logging is available, retain raw HTTP metadata and correlate requests with file-integrity alerts, WordPress audit events, process execution, and outbound network connections.

Mitigation and Patching

The immediate remediation is to upgrade AFFI – Affiliate Marketing for WooCommerce to the newest version released by VillaTheme or available through the official WordPress plugin channel. The retrieved advisory confirms that a mitigation or fix is available but does not expose the exact fixed version. After upgrading, verify that the installed release is newer than 1.0.10 and confirm the release status with VillaTheme or the WordPress update metadata.

A WP-CLI upgrade can be initiated with:

wp plugin update affi-affiliate-marketing-for-woo \
  --path=/var/www/html

Because the fixed version number is not confirmed in the available source material, do not use a successful command result alone as the remediation record. Capture the resulting version and compare it with the vendor’s stated fixed release. If the plugin is not required, removal is preferable to leaving an affected copy installed:

wp plugin deactivate affi-affiliate-marketing-for-woo \
  --path=/var/www/html

wp plugin delete affi-affiliate-marketing-for-woo \
  --path=/var/www/html

Test the update in staging when the site supports critical commerce operations, then deploy it through the organization’s normal change process. Take a backup and preserve logs before changing a system that may have been compromised.

If an immediate upgrade is impossible, deactivate the plugin and restrict access to the WordPress administration interface and any relevant application endpoints. Apply least-privilege controls so only necessary administrators and service accounts can manage plugins; this least-privilege IAM checklist can help structure that review. A temporary web-application firewall rule can reduce exposure, but no CVE-specific rule can be recommended because the vulnerable route and parameter are not published in the available material. Do not rely on a WAF as a substitute for removal or upgrade.

For endpoints used by WordPress administrators and incident responders, a reputable malware-detection product such as Malwarebytes may provide an additional layer of local scanning. It should supplement—not replace—plugin updates, server monitoring, and forensic investigation.

After remediation, review administrator and editor accounts, application passwords, API keys, scheduled tasks, recently modified PHP files, and web-server child processes. Rotate credentials if the affected plugin accepted untrusted requests while installed, particularly when suspicious activity is found. If compromise indicators are present, isolate the host, preserve forensic evidence, and rebuild from a trusted source rather than assuming that plugin replacement removed persistence.

References

The NVD record provides the CVE description, the affected product, the affected range through version 1.0.10, and the 9.8 CVSS score:

Patchstack’s advisory identifies the affected WordPress plugin and reports that mitigation or a fix is available. The retrieved page did not expose the exact fixed version or a complete technical root-cause description:

CISA’s catalog is the authoritative reference for current Known Exploited Vulnerabilities status. CVE-2026-104398 was reported as not listed at the time of the referenced check:

A secondary vulnerability index provides contextual status information, including an unconfirmed exploitation assessment. It should not replace the NVD or vendor material:

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-10

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.