Sceawere
Vulnerability Detail
CVE-2026-104398UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AFFI WooCommerce Object Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- VillaTheme
- Product
- AFFI – Affiliate Marketing for WooCommerce
- Attack Type
- Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T17:16:59.937Z",
"pubdate": "2026-10-10T17:16:59.937Z",
"executiveSummary": "The AFFI – Affiliate Marketing for WooCommerce plugin, version 1.0.10 and below, is susceptible to a Deserialization of Untrusted Data vulnerability.\nThis vulnerability, characterized as PHP Object Injection, allows a remote, unauthenticated attacker to manipulate serialized data processed by the plugin.\nSuccessful exploitation can lead to severe security implications, including remote code execution (RCE), arbitrary file deletion, or sensitive data disclosure, depending on the availability of gadget chains within the application's environment.\nThe flaw originates from the insecure handling of user-supplied input during the deserialization process, which lacks proper validation or signature verification.\nGiven that deserialization occurs before object instantiation, an attacker can supply a malicious payload that triggers unauthorized operations when the application attempts to reconstruct the serialized object.\nOrganizations utilizing this plugin are at high risk, as exploitation typically requires no prior authentication and can be performed over the network, potentially compromising the integrity and availability of the entire WordPress installation.",
"technicalDetails": "The root cause of the vulnerability lies in the use of the insecure PHP unserialize() function on user-controlled input without sufficient validation or integrity checks.\nIn PHP, the unserialize() function instantiates objects based on the provided serialized string. If an attacker can inject a custom serialized string, they can manipulate the state of objects within the application flow.\nThe attack flow begins when the plugin receives unsanitized input, typically via GET or POST parameters, which is subsequently passed to a deserialization routine. By crafting a payload containing a serialized object of an existing class (a 'gadget'), an attacker can influence the behavior of the application during object destruction or wakeup sequences.\nSpecifically, if the application environment includes common third-party libraries or plugin code that implements magic methods such as __destruct(), __wakeup(), or __toString(), these can be chained together to execute arbitrary code or perform unauthorized file system operations.\nBecause the vulnerability exists in the plugin's data processing logic, it is accessible to unauthenticated remote attackers. The payload is delivered via HTTP requests, allowing the attacker to bypass standard application layer security controls.\nUpon successful injection, the PHP engine reconstructs the malicious object. If the application environment contains 'pop chains' (Property Oriented Programming), the attacker can redirect program execution to unintended functions. For instance, an attacker could instantiate an object that, upon destruction, writes a file to the web root or invokes a system command via exec() or system() if the class properties are controlled to pass arguments into sensitive sinks.\nThe vulnerability is pervasive across all versions from n/a through 1.0.10. Given the widespread use of WooCommerce plugins, the potential for automated exploitation is high. Post-exploitation, an attacker can establish persistence, exfiltrate the WordPress database containing customer information, or pivot to the underlying server hosting the application. The impact is essentially total system compromise, assuming the PHP process has sufficient operating system privileges."
}