CVE-2026-6169
HIGHaffiliate-toolkit <= 3.8.5 - Authenticated (Editor+) Remote Code Execution
Title source: cnaDescription
The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization or sandboxing. This makes it possible for authenticated attackers, with Editor-level access and above, to execute arbitrary code on the server by injecting PHP into a plugin template.
References (4)
Core 4
Core References
Scores
CVSS v3
7.2
EPSS
0.0058
EPSS Percentile
43.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
cservit/affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display
< 3.8.4
Published
May 27, 2026
Tracked Since
May 27, 2026