CVE-2026-32558: unauthenticated privilege escalation in RedefiningTheWeb Affiliate Pro - Affiliate Program for WooCommerce & WordPress

An unauthenticated attacker can escalate privileges in the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin, allowing them to obtain elevated capabilities on a site running the plugin. CVE-2026-32558 affects the 8.x branch, specifically version 8.9.1 and earlier. No authentication is required to exploit the flaw; the attacker only needs network access to a site where the vulnerable plugin is active.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00483
CWE
CWE-266
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this vulnerability allows privilege elevation without any login on internet-facing WordPress sites; prioritize restricting exposure and applying vendor guidance when available.

What is CVE-2026-32558?

An unauthenticated attacker can escalate privileges in the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin, allowing them to obtain elevated capabilities on a site running the plugin. CVE-2026-32558 affects the 8.x branch, specifically version 8.9.1 and earlier. No authentication is required to exploit the flaw; the attacker only needs network access to a site where the vulnerable plugin is active.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of RedefiningTheWeb Affiliate Pro - Affiliate Program for WooCommerce & WordPress are affected?

BRANCHAFFECTEDFIXED
8.x8.9.1 and earlier

Is CVE-2026-32558 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-32558

  1. Isolate or restrict external access to WordPress admin interfaces and plugin endpoints until a vendor fix is available.
  2. Monitor logs for unusual account creation, privilege changes, or administrative activity related to the Affiliate Pro plugin.
  3. Follow the vendor's security advisory and apply any updates or recommended configuration changes as soon as they are published.
  4. Temporarily deactivate or remove the Affiliate Pro plugin (versions 8.9.1 and earlier) from internet-accessible sites until patched.

Frequently asked questions

Is CVE-2026-32558 being actively exploited?

There are no public reports of exploitation of CVE-2026-32558 as of 2026-09-29.

Which Affiliate Pro - Affiliate Program for WooCommerce & WordPress versions are affected by CVE-2026-32558?

CVE-2026-32558 affects the Affiliate Pro plugin 8.x branch, specifically version 8.9.1 and earlier.

Is there a patch for CVE-2026-32558?

No fixed version is listed for CVE-2026-32558 in the provided facts; follow the vendor's guidance and apply updates when the vendor releases a patch.

Does CVE-2026-32558 require authentication?

No, CVE-2026-32558 is an unauthenticated privilege escalation in the Affiliate Pro plugin and does not require a valid login to exploit.

References