{
 "id": "WPSEC-2026-0533",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0533/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0533/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0533/index.md",
 "title": "affiliate-toolkit <= 3.9.0 - Authenticated (Contributor+) Remote Code Execution via Template Reference",
 "description": "The affiliate-toolkit plugin for WordPress is vulnerable to Remote Code Execution in versions 3.1.9 up to, and including, 3.9.0. Numeric template references, such as the 'template' attribute of the plugin's shortcodes or the template render AJAX action, were resolved to any post ID without verifying that the post is a template post, and template content taken from that post was compiled and executed by the plugin's template engine. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary code on the server. This is due to an incomplete fix for CVE-2026-6169.",
 "plugin": {
  "slug": "affiliate-toolkit-starter",
  "name": "affiliate-toolkit",
  "full_name": "affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display",
  "wordpress_org": "https://wordpress.org/plugins/affiliate-toolkit-starter/",
  "advisories_url": "https://wpsec.com/vuln/plugin/affiliate-toolkit-starter/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/affiliate-toolkit-starter"
 },
 "type": "RCE",
 "cwe": [
  "CWE-94"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.8,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.1.9",
    "from_inclusive": true,
    "to": "3.9.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.1.9 before 3.9.1"
  ]
 },
 "introduced_in": "3.1.9",
 "fixed_in": "3.9.1",
 "remediation": "Update to 3.9.1 or later.",
 "fix_released": "2026-10-06T07:37:43+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T12:34:54.067529+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0533/",
  "https://plugins.svn.wordpress.org/affiliate-toolkit-starter/tags/3.9.1/",
  "https://wordpress.org/plugins/affiliate-toolkit-starter/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/affiliate-toolkit-starter",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}