affiliate-toolkit <= 3.9.0 - Authenticated (Contributor+) Remote Code Execution via Template Reference

High 8.8 CWE-94Fixed in 3.9.1
ID
WPSEC-2026-0533
Plugin
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display (affiliate-toolkit-starter)
Affected
from 3.1.9 before 3.9.1
Remediation
Update to 3.9.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-94
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
affiliate-toolkit on WPSec AttackSurface
Fix released
Published

Description

The affiliate-toolkit plugin for WordPress is vulnerable to Remote Code Execution in versions 3.1.9 up to, and including, 3.9.0. Numeric template references, such as the 'template' attribute of the plugin's shortcodes or the template render AJAX action, were resolved to any post ID without verifying that the post is a template post, and template content taken from that post was compiled and executed by the plugin's template engine. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary code on the server. This is due to an incomplete fix for CVE-2026-6169.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0