CVE-2026-32558 describes an unauthenticated privilege escalation vulnerability affecting the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin in versions up to and including 8.9.1. The vulnerability allows unauthenticated attackers to escalate their privileges, posing a significant security risk to WordPress and WooCommerce installations using this plugin. The flaw has been documented by both the NVD (National Vulnerability Database) and Patchstack. No authentication is required to exploit this vulnerability, making it particularly dangerous for affected sites. Users are advised to update the plugin beyond version 8.9.1 to remediate the issue. The vulnerability is classified as high severity given the unauthenticated nature of the exploit and the potential for full privilege escalation.