Remote Code Execution Vulnerability in Affiliate Toolkit Plugin for WordPress
CVE-2026-6169

7.2HIGH

What is CVE-2026-6169?

The Affiliate Toolkit plugin for WordPress, up to and including version 3.8.5, exhibits a security flaw that permits remote code execution. This vulnerability arises from the use of the BladeOne templating engine's runString() method, which compiles user-provided template content into PHP code and executes it using eval() without adequate sanitization or sandboxing measures. As a result, authenticated attackers with Editor-level access or higher can exploit this weakness to inject arbitrary PHP code into a plugin template, potentially compromising the server’s integrity.

Affected Version(s)

affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display 0 <= 3.8.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Quang Truong
.