CVE-2026-104398
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Oct 10, 2026
Vendor
unknown
Description
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.