CVE-2026-6169
Last modified
CVE-2026-6169 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization or sandboxing. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization or sandboxing. This makes it possible for authenticated attackers, with Editor-level access and above, to execute arbitrary code on the server by injecting PHP into a plugin template.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6169?
How severe is CVE-2026-6169?
How do I fix CVE-2026-6169?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-61682kcp is a Kubernetes-like control plane for form-factors and …9.9
- CVE-2026-61684FastGPT is a knowledge-based AI application platform. In 4.1…8.8
- CVE-2026-61685ReactPress is a publishing system for React developers. Prio…7.5
- CVE-2026-61686SolidInvoice is an open-source invoicing platform. Prior to …7.5
- CVE-2026-61687Hatchet is a platform for orchestrating background tasks, AI…7.1
- CVE-2026-61688SolidInvoice is an open-source invoicing platform. Prior to …6.5
- CVE-2026-61690Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipA…6.5
- CVE-2026-61692Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-61695Wire provides gRPC and protocol buffers for Android, Kotlin,…7.5
- CVE-2026-61696Forem is open source software for building communities. In v…6.3
- CVE-2026-61699nebula-mesh is a self-hosted control plane for Slack Nebula …8.1
- CVE-2026-61700MariaDB Connector/J is used to connect applications develope…3.7
Are you affected by CVE-2026-6169?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
