Skip to main content
QUIETLYTIC
Vulnerability

Affiliate Pro - Affiliate Program for WooCommerce & WordPress Privilege Escalation (CVE-2026-32558)

CVE-2026-32558 is a CVSS 9.8 unauthenticated privilege escalation flaw in the Affiliate Pro WordPress plugin, reported exploited by VulnCheck KEV.

CVE-2026-32558
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Affiliate Pro - Affiliate Program for WooCommerce & WordPress, Affiliate Pro (through 8.9.1)

CVE-2026-32558 carries a CVSS 3.1 base score of 9.8 against Affiliate Pro - Affiliate Program for WooCommerce & WordPress, a plugin published by RedefiningTheWeb for running affiliate programs on WooCommerce stores. NVD classifies it as CWE-266 (Incorrect Privilege Assignment) and states the affected range as versions up to and including 8.9.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 24, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-32558 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s own summary is brief: an unauthenticated privilege escalation in Affiliate Pro versions through 8.9.1. Patchstack’s vulnerability database, cited directly from NVD’s reference list, tracks the same CVE under the identical CWE-266 classification our source data carries. As with several other brief-summary NVD records in our recent coverage, the description does not specify which privileged role or action becomes reachable, or what request path triggers the escalation.

We report NVD’s classification and affected-version boundary as stated. This is a gap in publicly available technical detail, not a gap we are choosing to fill with speculation.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-266 classification, and the affected-version ceiling (8.9.1) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00268, a 19.1st percentile score as of our ingestion — on the lower end of our recent KEV coverage.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s summary states only the affected ceiling.

Why this matters

Affiliate management plugins sit adjacent to a WooCommerce store’s payment and commission logic, which makes an unauthenticated privilege-escalation path in one worth taking seriously even without a fully documented mechanism: the category of data and functionality typically reachable from an elevated role on this kind of plugin includes commission records, affiliate payout configuration, and potentially broader WordPress capabilities depending on how the plugin’s role system integrates with core WordPress roles.

The below-midpoint EPSS score is worth noting without over-reading it: EPSS reflects a statistical model’s assessment of broad exploitation likelihood across the entire scored CVE population, not a judgment about this specific flaw’s severity, and it does not override the CVSS 9.8 score or the confirmed VulnCheck exploitation report as grounds for prioritizing a fix.

Frequently Asked Questions

What is CVE-2026-32558? A CVSS 9.8 unauthenticated privilege escalation vulnerability (CWE-266) in the Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin, affecting versions up to and including 8.9.1.

Is CVE-2026-32558 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 24, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 8.9.1 are affected; confirm directly with the vendor’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-32558, which cites Patchstack’s vulnerability database entry. Exploitation status and the August 24, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools