PatchSiren

WC Vendors CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WC Vendors CVE published 2026-09-02

CVE-2026-81428

The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when saving product variations, allowing authenticated users with the vendor role to modify product variations belonging to other vendors, and to change the status and title of arbitrary posts, via IDOR. This issue enables unauthorized modifications to product variations and posts, potentially [truncated]

MEDIUM WC Vendors CVE published 2026-09-02

CVE-2026-81426

The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request. This vulnerability affects users with logged-in vendor accounts and could lead to unauthorized changes in shipment status. Operators of affected syste [truncated]