CVE-2026-106606: Yith Woocommerce Affiliates
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Affiliates yith-woocommerce-affiliates allows Object Injection.This issue affects YITH WooCommerce Affiliates: from n/a through 3.31.0.
Affected products
- Yith Yith Woocommerce Affiliates: up to and including 3.31.0
Published 2026-10-10. Last modified 2026-10-10.