Description
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Published: 2026-08-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to elevate privileges within the Affiliate Pro plugin, enabling them to perform actions reserved for administrators or other privileged users. The flaw is a classic Example of improper privilege assignment (CWE-266) which could lead to unauthorized configuration changes, data exposure, or further exploitation of the host system.

Affected Systems

The affected product is Affiliate Pro – Affiliate Program for WooCommerce & WordPress by RedefiningTheWeb. Versions 8.9.1 and earlier are vulnerable. Users operating these plugin versions on a WordPress site are at risk.

Risk and Exploitability

The CVSS score of 9.8 highlights the severity of this flaw. With no authentication required, an attacker can exploit it remotely without any prior access, making it highly dangerous. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the high severity and lack of prerequisite conditions indicate a meaningful risk for exposed WordPress sites running the vulnerable plugin.

Generated by OpenCVE AI on August 24, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Affiliate Pro to the latest patched version that eliminates the privilege escalation flaw.
  • If the update cannot be applied immediately, disable the plugin or restrict its activation to trusted administrators until a patch is available.
  • After applying the patch, verify that access controls are correctly applied so that only users with appropriate roles can invoke privileged plugin functions.

Generated by OpenCVE AI on August 24, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redefiningtheweb
Redefiningtheweb affiliate Pro - Affiliate Program For Woocommerce & Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Redefiningtheweb
Redefiningtheweb affiliate Pro - Affiliate Program For Woocommerce & Wordpress
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Title WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redefiningtheweb Affiliate Pro - Affiliate Program For Woocommerce & Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:07.003Z

Reserved: 2026-03-12T11:12:48.310Z

Link: CVE-2026-32558

cve-icon Vulnrichment

Updated: 2026-08-24T12:48:00.283Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T12:16:51.877

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-32558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:11Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment