PatchSiren cyber security CVE debrief
CVE-2026-106606 YITH CVE debrief
The CVE-2026-106606 vulnerability in the YITH WooCommerce Affiliates plugin for WordPress, versions up to 3.31.0, allows for PHP Object Injection due to deserialization of untrusted data. This issue, classified as a Deserialization of Untrusted Data vulnerability, has a CVSS score of 7.2 and is considered HIGH severity. The vulnerability was published on October 10, 2026, and has not been modified since then.
- Vendor
- YITH
- Product
- YITH WooCommerce Affiliates
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations using the YITH WooCommerce Affiliates plugin should assess their exposure and take necessary actions to mitigate the vulnerability.
Why it matters
CVE-2026-106606 is a high-severity vulnerability in the YITH WooCommerce Affiliates plugin for WordPress, allowing for PHP Object Injection. Defenders should assess exposure, verify vendor remediation, and monitor for potential exploitation attempts.
- Potential for object injection attacks leading to code execution
- Possible unauthorized access or modification of sensitive data
- Risk of privilege escalation in affected WordPress environments
- Need for verification of plugin version and vendor remediation status
Technical summary
The YITH WooCommerce Affiliates plugin for WordPress, versions up to 3.31.0, is vulnerable to PHP Object Injection. This is due to the deserialization of untrusted data, which can lead to object injection attacks. The vulnerability has a CVSS score of 7.2, indicating high severity.
Defensive priority
Defenders should prioritize assessing exposure and verifying if their systems are affected by this vulnerability, especially those using the YITH WooCommerce Affiliates plugin.
Recommended defensive actions
- Assess exposure: Verify if the YITH WooCommerce Affiliates plugin version is less than or equal to 3.31.0.
- Verify vendor remediation: Check for updates or patches provided by YITH.
- Inventory check: Review system inventory for installations of the YITH WooCommerce Affiliates plugin.
- Monitoring: Monitor system logs for potential exploitation attempts.
Evidence notes
The evidence for this vulnerability comes from the CVE Program and the National Vulnerability Database (NVD). The CVE record and NVD detail page provide information on the vulnerability's existence, its CVSS score, and affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106606.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.