CRITICAL 9.8 CVE-2026-104398 Published 10 Oct 2026

VillaTheme AFFI WooCommerce Plugin Object Injection Vulnerability

Worried this affects your website?

A Deserialization of Untrusted Data vulnerability has been reported in VillaTheme AFFI – Affiliate Marketing for WooCommerce.

The flaw allows Object Injection.

  • Affected versions: from n/a through 1.0.10

Reference: CVE-2026-104398 on NVD

← Back to Security News