CRITICAL
9.8 CVE-2026-104398 Published 10 Oct 2026
VillaTheme AFFI WooCommerce Plugin Object Injection Vulnerability
Worried this affects your website?
A Deserialization of Untrusted Data vulnerability has been reported in VillaTheme AFFI – Affiliate Marketing for WooCommerce.
The flaw allows Object Injection.
- Affected versions: from n/a through 1.0.10
Reference: CVE-2026-104398 on NVD
← Back to Security News