Sceawere

Vulnerability Detail

CVE-2026-106606UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YITH WooCommerce Affiliates Object Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
YITH
Product
YITH WooCommerce Affiliates
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T08:17:04.353Z",
  "pubdate": "2026-10-10T08:17:04.353Z",
  "executiveSummary": "The YITH WooCommerce Affiliates plugin is susceptible to an Object Injection vulnerability caused by the insecure deserialization of untrusted data.\nThis vulnerability affects versions from n/a through 3.31.0 and poses a critical risk to the integrity and availability of the host WordPress environment.\nThe flaw allows an unauthenticated or authenticated attacker to inject malicious serialized objects into the application, which are subsequently processed by the PHP unserialize() function.\nSuccessful exploitation can lead to arbitrary code execution, unauthorized file system access, or sensitive data exposure, depending on the available gadget chains present in the environment.\nThe risk is heightened due to the potential for remote exploitation without requiring high-level administrative privileges, assuming the vulnerable endpoint is reachable by the attacker.\nDefensive posture requires immediate attention to plugin updates or the implementation of strict input validation mechanisms to prevent the instantiation of arbitrary PHP objects.",
  "technicalDetails": "The core vulnerability lies in the improper handling of user-supplied input that is passed to the PHP unserialize() function within the YITH WooCommerce Affiliates plugin.\nWhen an application unserializes user-controlled data without adequate validation or sanitization, it permits an attacker to manipulate the properties of objects currently in memory or instantiate new objects of existing classes.\nThe attack flow typically initiates when an attacker crafts a malicious serialized string containing specific class definitions and property values. By supplying this payload to the vulnerable endpoint, the attacker influences the execution flow of the application during the object reconstruction process.\nIf the application includes 'gadget chains'—a sequence of existing code components that can be chained together during the magic method execution (such as __wakeup(), __destruct(), or __toString())—the attacker can achieve Remote Code Execution (RCE).\nIn the context of the YITH WooCommerce Affiliates plugin (versions up to 3.31.0), the lack of signature validation or integrity checks on the deserialized stream allows the attacker to bypass standard input filtering.\nThe exploitation process follows these steps: 1) Identification of the vulnerable input parameter that routes data to a deserialization sink. 2) Analysis of the codebase to identify available classes with exploitable magic methods. 3) Generation of a crafted serialized payload designed to trigger a specific sequence of operations. 4) Injection of the payload via an HTTP request. 5) Execution of the payload by the server upon processing the unserialization command.\nThe impact is significant because the attacker can interact with the server's filesystem, database, or network configuration, effectively escalating their control from simple data input to full system compromise. The severity depends on the PHP environment configuration, but the presence of common libraries often provides sufficient gadgets to facilitate a complete exploit chain.\nAs this flaw involves object instantiation, it does not rely on traditional SQL injection vectors but rather on the logic flaws inherent in PHP's object serialization mechanism, making it highly potent against WordPress installations relying on default or outdated component structures."
}
CVE-2026-106606: YITH WooCommerce Affiliates Object Injection (HIGH Severity, CVSS: 7.2) | Sceawere