Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
Published: 2026-10-07
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Data Compromise
Action: Apply Patch
AI Analysis

Impact

The affiliate‑toolkit plugin contains a blind SQL injection flaw that allows an attacker to send specially crafted input that is concatenated into database queries. This weakness can be exploited to read or extract arbitrary data from the shop or content database, potentially revealing sensitive user information or credentials. The vulnerability exists in all releases up to and including version 3.9.1 and is listed as a CWEs for the specific weakness of SQL injection.

Affected Systems

The flaw is present in SERVIT Software Solutions affiliate‑toolkit plugin, version 3.9.1 and earlier. Users running this plugin on a WordPress installation are at risk, regardless of the host server configuration or the plugin’s usage scope within the site.

Risk and Exploitability

The CVSS score of 7.6 classifies the issue as high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack surface is via web requests targeting the plugin’s parameters, and because the injection is blind, an attacker would need to probe the response to infer successful exploitation. If successful, the attacker could gain read access to the database and thereby compromise data confidentiality.

Generated by OpenCVE AI on October 7, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the affiliate‑toolkit plugin to a version that contains the SQL injection fix (for example, 3.9.2 or later).
  • Limit access to the plugin’s administrative and configuration pages to privileged accounts and block or restrict external network access where possible.
  • Run automated web‑application vulnerability scans to detect additional injection points and verify that the patched plugin behaves correctly and does not introduce further weaknesses.

Generated by OpenCVE AI on October 7, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
Title WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T10:26:38.797Z

Reserved: 2026-04-29T09:05:20.866Z

Link: CVE-2026-42721

cve-icon Vulnrichment

Updated: 2026-10-07T10:26:35.920Z

cve-icon NVD

Status : Received

Published: 2026-10-07T10:17:35.870

Modified: 2026-10-07T11:17:19.500

Link: CVE-2026-42721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:30:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')