# affiliate-toolkit <= 3.9.0 - Authenticated (Contributor+) Remote Code Execution via Template Reference

- **ID:** WPSEC-2026-0533
- **Plugin:** affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display (`affiliate-toolkit-starter`), https://wordpress.org/plugins/affiliate-toolkit-starter/
- **Affected versions:** from 3.1.9 before 3.9.1
- **Fixed in:** 3.9.1 (Update to 3.9.1 or later.)
- **Severity:** High 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-94
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/affiliate-toolkit-starter
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0533/

## Description

The affiliate-toolkit plugin for WordPress is vulnerable to Remote Code Execution in versions 3.1.9 up to, and including, 3.9.0. Numeric template references, such as the 'template' attribute of the plugin's shortcodes or the template render AJAX action, were resolved to any post ID without verifying that the post is a template post, and template content taken from that post was compiled and executed by the plugin's template engine. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute arbitrary code on the server. This is due to an incomplete fix for CVE-2026-6169.

## References

- https://wpsec.com/vuln/WPSEC-2026-0533/
- https://plugins.svn.wordpress.org/affiliate-toolkit-starter/tags/3.9.1/
- https://wordpress.org/plugins/affiliate-toolkit-starter/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0533/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
