PatchSiren

WC Lovers CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL WC Lovers CVE published 2026-09-02

CVE-2026-81286

A critical vulnerability was found in WCFM Marketplace plugin versions <= 3.8.1. This vulnerability allows unauthenticated SQL injection attacks with a CVSS score of 9.3.