PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106606 YITH CVE debrief

The CVE-2026-106606 vulnerability in the YITH WooCommerce Affiliates plugin for WordPress, versions up to 3.31.0, allows for PHP Object Injection due to deserialization of untrusted data. This issue, classified as a Deserialization of Untrusted Data vulnerability, has a CVSS score of 7.2 and is considered HIGH severity. The vulnerability was published on October 10, 2026, and has not been modified since then.

Vendor
YITH
Product
YITH WooCommerce Affiliates
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations using the YITH WooCommerce Affiliates plugin should assess their exposure and take necessary actions to mitigate the vulnerability.

Why it matters

CVE-2026-106606 is a high-severity vulnerability in the YITH WooCommerce Affiliates plugin for WordPress, allowing for PHP Object Injection. Defenders should assess exposure, verify vendor remediation, and monitor for potential exploitation attempts.

  • Potential for object injection attacks leading to code execution
  • Possible unauthorized access or modification of sensitive data
  • Risk of privilege escalation in affected WordPress environments
  • Need for verification of plugin version and vendor remediation status

Technical summary

The YITH WooCommerce Affiliates plugin for WordPress, versions up to 3.31.0, is vulnerable to PHP Object Injection. This is due to the deserialization of untrusted data, which can lead to object injection attacks. The vulnerability has a CVSS score of 7.2, indicating high severity.

Defensive priority

Defenders should prioritize assessing exposure and verifying if their systems are affected by this vulnerability, especially those using the YITH WooCommerce Affiliates plugin.

Recommended defensive actions

  • Assess exposure: Verify if the YITH WooCommerce Affiliates plugin version is less than or equal to 3.31.0.
  • Verify vendor remediation: Check for updates or patches provided by YITH.
  • Inventory check: Review system inventory for installations of the YITH WooCommerce Affiliates plugin.
  • Monitoring: Monitor system logs for potential exploitation attempts.

Evidence notes

The evidence for this vulnerability comes from the CVE Program and the National Vulnerability Database (NVD). The CVE record and NVD detail page provide information on the vulnerability's existence, its CVSS score, and affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106606 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106606

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106606 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106606

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.