Junglewise Threat Intelligence

CVE-2026-32558: Affiliate Pro Affiliate Program for WooCommerce privilege escalation

CVE-2026-32558 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

Affiliate Pro is a popular WordPress plugin for managing affiliate marketing programs in WooCommerce stores. An unauthenticated attacker can exploit a privilege escalation vulnerability to gain full administrator access to the WordPress site, potentially compromising customer data, payment systems, and the entire store infrastructure.

Technical details

The plugin contains an unauthenticated privilege escalation vulnerability that allows an attacker to elevate from an unauthenticated or low-privilege user to full administrator access. The vulnerability is classified as an identification and authentication failure (OWASP A7), enabling complete compromise of the WordPress installation. Attack vector is network-based with no authentication required, making it trivially exploitable. This vulnerability has been confirmed as exploited in the wild and widely used in mass-exploitation campaigns. No official patch is available; vendors advise immediate mitigation via security plugins or update to a patched version once released.

Affected products

  • Affiliate Pro Affiliate Program for WooCommerce & WordPress <= 8.9.1

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: kev added: Known to be exploited in the wild
  • 2026-06-30: reported: Initially reported by 0xd4rk5id3

References