CVE-2026-104398: Villatheme Affi – Affiliate Marketing For Woocommerce
Critical severity, CVSS 9.8.
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.
Affected products
- Villatheme Affi – Affiliate Marketing For Woocommerce: up to and including 1.0.10
Published 2026-10-10. Last modified 2026-10-10.