A vulnerability was found in cservit affiliate-toolkit Plugin up to 3.8.8 on WordPress and classified as problematic . Affected is an unknown function. Such manipulation of the argument orderby leads to sql injection. This vulnerability is referenced as CVE-2026-12743 . It is possible to launch the attack remotely. No exploit is available.