Junglewise Threat Intelligence

CVE-2026-65558: WPCenter AffiliateX SSRF in WordPress plugin

CVE-2026-65558 · Severity: medium · CVSS 5.4 · Published 2026-07-27

Executive brief

AffiliateX is a WordPress plugin used by website owners to manage affiliate marketing links and content. A security vulnerability in versions 2.3.5 and earlier allows unauthenticated attackers to force the website to make unauthorized requests to internal or external servers. This could lead to the exposure of sensitive information from other services running on the same network or be used to bypass security controls.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the WPCenter AffiliateX plugin for WordPress (versions <= 2.3.5). The flaw allows an unauthenticated remote attacker to submit a crafted request that forces the server to perform web requests to arbitrary domains or internal network resources. While the attack complexity is rated as high, a successful exploit could allow an attacker to probe internal network services or access sensitive data that is not intended to be public. The issue is addressed in version 2.3.6.

Affected products

  • WPCenter AffiliateX <= 2.3.5

Timeline

  • 2026-07-09: other: Reported by researcher Ananda Dhakal
  • 2026-07-24: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD
  • 2026-07-27: patched: Fixed in version 2.3.6

References