DIRAS TAKE
Urgent: this vulnerability allows privilege elevation without any login on internet-facing WordPress sites; prioritize restricting exposure and applying vendor guidance when available.
What is CVE-2026-32558?
An unauthenticated attacker can escalate privileges in the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin, allowing them to obtain elevated capabilities on a site running the plugin. CVE-2026-32558 affects the 8.x branch, specifically version 8.9.1 and earlier. No authentication is required to exploit the flaw; the attacker only needs network access to a site where the vulnerable plugin is active.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of RedefiningTheWeb Affiliate Pro - Affiliate Program for WooCommerce & WordPress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 8.x | 8.9.1 and earlier |
Is CVE-2026-32558 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-32558
- Isolate or restrict external access to WordPress admin interfaces and plugin endpoints until a vendor fix is available.
- Monitor logs for unusual account creation, privilege changes, or administrative activity related to the Affiliate Pro plugin.
- Follow the vendor's security advisory and apply any updates or recommended configuration changes as soon as they are published.
- Temporarily deactivate or remove the Affiliate Pro plugin (versions 8.9.1 and earlier) from internet-accessible sites until patched.
Frequently asked questions
Is CVE-2026-32558 being actively exploited?
There are no public reports of exploitation of CVE-2026-32558 as of 2026-09-29.
Which Affiliate Pro - Affiliate Program for WooCommerce & WordPress versions are affected by CVE-2026-32558?
CVE-2026-32558 affects the Affiliate Pro plugin 8.x branch, specifically version 8.9.1 and earlier.
Is there a patch for CVE-2026-32558?
No fixed version is listed for CVE-2026-32558 in the provided facts; follow the vendor's guidance and apply updates when the vendor releases a patch.
Does CVE-2026-32558 require authentication?
No, CVE-2026-32558 is an unauthenticated privilege escalation in the Affiliate Pro plugin and does not require a valid login to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-32558
- cve.org/CVERecord?id=CVE-2026-32558
- patchstack.com/database/wordpress/plugin/wp-wc-affiliate-program/vulnerability/wordpress-affiliate-pro-affiliate-program-for-woocommerce-wordpress-plugin-8-9-1-privilege-escalation-vulnerability?_s_id=cve
- All RedefiningTheWeb CVEs on CVE Radar
- CVEs published in September 2026