CVE-2026-102390: Villatheme Affi – Affiliate Marketing For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9.

Affected products

  • Villatheme Affi – Affiliate Marketing For Woocommerce: up to and including 1.0.9

Published 2026-10-01. Last modified 2026-10-01.