SECURITYCRITICALCVE-2026-104398

CVE-2026-104398: Critical Object Injection in WooCommerce AFFI Affiliate Marketing Plugin

A deserialization flaw in VillaTheme's AFFI WooCommerce plugin allows unauthenticated PHP object injection, risking full site takeover.

Dylan H.

Security Team

October 11, 2026
5 min read
CVE-2026-104398: Critical Object Injection in WooCommerce AFFI Affiliate Marketing Plugin

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • AFFI – Affiliate Marketing for WooCommerce, through version 1.0.10

Overview

A critical vulnerability has been disclosed in AFFI – Affiliate Marketing for WooCommerce, a WordPress plugin from VillaTheme used to run affiliate programs on WooCommerce storefronts. Tracked as CVE-2026-104398 with a maximum CVSS score of 9.8, the flaw is a Deserialization of Untrusted Data issue (CWE-502) that allows an unauthenticated attacker to trigger PHP Object Injection — a class of bug that commonly leads to remote code execution, arbitrary file operations, or full site compromise depending on what "magic methods" exist elsewhere in the WordPress install.

The vulnerability was assigned by Patchstack and affects every release of the plugin through version 1.0.10.


Technical Details

FieldValue
CVE IDCVE-2026-104398
SeverityCritical (CVSS 9.8)
CWECWE-502 — Deserialization of Untrusted Data
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
User InteractionNone
ImpactConfidentiality, Integrity, Availability — all High
Affected VersionsAFFI – Affiliate Marketing for WooCommerce, n/a through 1.0.10
Fixed Version1.0.11 or later
AssignerPatchstack

How It Works

The AFFI plugin processes serialized PHP data from untrusted input without adequate validation before passing it to PHP's deserialization functions. When an attacker-controlled serialized string reaches unserialize() (or an equivalent call) unchecked, PHP will instantiate whatever object classes the string specifies — including classes defined by WordPress core, other installed plugins, or themes.

This is the mechanism behind PHP Object Injection: the attacker doesn't need to find a bug in AFFI's own logic beyond the missing input validation. Instead, they craft a serialized payload that, once deserialized, triggers a "POP chain" (Property-Oriented Programming chain) using magic methods such as __wakeup(), __destruct(), or __toString() that already exist somewhere in the site's loaded code. Depending on what classes are available, this can escalate to arbitrary file writes, SQL injection, or remote code execution.

Because the flaw requires no authentication and no user interaction, any WordPress site with the vulnerable plugin active is exposed directly over the network.


Impact Assessment

Who Is At Risk

Any WooCommerce store running AFFI – Affiliate Marketing for WooCommerce version 1.0.10 or earlier is vulnerable, including sites that:

  • Run affiliate or referral programs through the plugin's public-facing endpoints
  • Have other plugins or themes installed that expose exploitable magic methods (increasing the severity of what the object injection can achieve)
  • Cannot patch immediately due to custom affiliate-program integrations built on top of the plugin

Potential Attack Chains

  1. Discovery — Attacker fingerprints the target site as running AFFI via plugin enumeration or asset paths
  2. Payload Crafting — Attacker builds a serialized PHP object payload targeting a POP chain available in the site's WordPress core, theme, or other plugins
  3. Injection — Attacker submits the payload to an AFFI endpoint that deserializes untrusted input
  4. Exploitation — Deserialization triggers magic methods that write files, execute code, or otherwise compromise the site

The practical severity of any individual deserialization bug like this one depends heavily on what other code is loaded on the same WordPress install — a site with a vulnerable "gadget chain" library present can go from object injection straight to remote code execution.


Mitigation

Immediate Actions

  • Update AFFI – Affiliate Marketing for WooCommerce to version 1.0.11 or later as soon as it is available in your WordPress plugin dashboard
  • If an immediate update isn't possible, consider deactivating the plugin until patched, particularly on stores handling payment or customer PII
  • Review recent file modification timestamps in wp-content/ for unexpected changes that could indicate exploitation

Detection Opportunities

  • Monitor web server logs for unusual POST requests to AFFI-related endpoints containing serialized-PHP-style strings (look for patterns beginning with O:, a:, or s: followed by digits)
  • Use a web application firewall (WAF) rule set that flags PHP serialization payloads in untrusted input fields
  • Audit for unexpected new admin users, scheduled tasks, or modified core files following any suspected exploitation window

Defence-in-Depth

  • Keep all WordPress plugins, themes, and core up to date — object injection severity often depends on other installed code providing the exploitable gadget chain
  • Minimize the number of active plugins to reduce the available attack surface for POP-chain exploitation
  • Run a reputable WordPress security plugin or managed WAF capable of virtually patching known plugin CVEs

Discovery & Disclosure

CVE-2026-104398 was reserved on October 2, 2026 and published on October 10, 2026, with Patchstack as the assigning CNA. As of publication, the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit has surfaced in open research repositories. Given the unauthenticated, zero-interaction attack path and maximum severity score, site administrators should treat patching as urgent rather than wait for confirmed in-the-wild exploitation.


References