Description
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Potential Remote Code Execution via Object Injection
Action: Immediate Patch
AI Analysis

Impact

Deserialization of untrusted data in YITH WooCommerce Affiliates versions up to 3.31.0 allows a PHP Object Injection flaw, classified as CWE‑502. An attacker can supply crafted serialized objects that the plugin unserializes, potentially leading to arbitrary code execution, data tampering, or disclosure. The vulnerability resides in the plugin’s handling of dynamic data during processing.

Affected Systems

The YITH WooCommerce Affiliates plugin for WordPress is affected. All installations using version 3.31.0 or earlier are vulnerable; versions 3.31.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.2 denotes moderate‑to‑high severity. No EPSS score is provided, so the current exploitation likelihood is unclear, but the lack of a KEV listing indicates no known widespread attacks yet. Attackers would need to supply malicious serialized data to the plugin, which could be delivered via crafted requests or input fields exposed by the plugin’s interface, potentially enabling remote code execution if successful.

Generated by OpenCVE AI on October 10, 2026 at 08:22 UTC.

Remediation

Vendor Solution

Update the WordPress YITH WooCommerce Affiliates plugin to the latest available version (at least 3.31.1).


OpenCVE Recommended Actions

  • Update YITH WooCommerce Affiliates to version 3.31.1 or later
  • If an immediate update is not possible, disable or remove the plugin from the WordPress installation until the patch is applied
  • Validate or sanitize any user‑supplied serialized data before it is processed by plugins, ensuring only trusted sources are deserialized

Generated by OpenCVE AI on October 10, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0.
Title WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T07:00:33.921Z

Reserved: 2026-10-07T00:21:31.996Z

Link: CVE-2026-106606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:04.353

Modified: 2026-10-10T08:17:04.353

Link: CVE-2026-106606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data