← Back to overview

CVE-2026-32558 describes an unauthenticated privilege escalation vulnerability affecting the Affiliate Pro plugin for WooCommerce and WordPress in versions 8.9.1 and below. The vulnerability allows unauthenticated attackers to escalate their privileges on affected WordPress installations. This represents a critical security risk as no authentication is required to exploit the flaw. The issue was documented by both the NVD (NIST) and Patchstack security databases. WordPress site owners using the Affiliate Pro plugin should update immediately to a patched version. The vulnerability is classified as high severity given that it enables privilege escalation without any credentials.

Affected products

  • Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1

Related CVE's

  • CVE-2026-32558

Categories

  • Identity & Access
  • Web Technologies