Remote Code Execution Vulnerability in Affiliate Toolkit Plugin for WordPress
CVE-2026-6169
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-6169?
The Affiliate Toolkit plugin for WordPress, up to and including version 3.8.5, exhibits a security flaw that permits remote code execution. This vulnerability arises from the use of the BladeOne templating engine's runString() method, which compiles user-provided template content into PHP code and executes it using eval() without adequate sanitization or sandboxing measures. As a result, authenticated attackers with Editor-level access or higher can exploit this weakness to inject arbitrary PHP code into a plugin template, potentially compromising the server’s integrity.
Affected Version(s)
affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display 0 <= 3.8.4