affiliate-toolkit <= 3.9.0 - Authenticated (Contributor+) Remote Code Execution via Template Reference
- ID
- WPSEC-2026-0533
- Plugin
- affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display (affiliate-toolkit-starter)
- Affected
- from 3.1.9 before 3.9.1
- Remediation
- Update to 3.9.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-94
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- affiliate-toolkit on WPSec AttackSurface
- Fix released
- Published
Description
The affiliate-toolkit plugin for WordPress is vulnerable to Remote Code Execution in versions 3.1.9 up to, and including, 3.9.0. Numeric template references, such as the 'template' attribute of the plugin's shortcodes or the template render AJAX action, were resolved to any post ID without verifying that the post is a template post, and template content taken from that post was compiled and executed by the plugin's template engine. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary code on the server. This is due to an incomplete fix for CVE-2026-6169.
References
- https://wpsec.com/vuln/WPSEC-2026-0533/
- https://plugins.svn.wordpress.org/affiliate-toolkit-starter/tags/3.9.1/
- https://wordpress.org/plugins/affiliate-toolkit-starter/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS