These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2. This vulnerability is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query, which makes it possible for unauthenticated attacke [truncated]
The WCFM – Frontend Manager for WooCommerce plugin for WordPress has an authorization bypass vulnerability in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. As a result, unauthenticated attackers can inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and [truncated]
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Vendor-level access and above, to inject arbitrary web scripts in pages that will execute [truncated]
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This vulnerability allows authenticated attackers with subscriber-level access and above to archive arbitrary vendors' products, toggle the featured status on arbitrar [truncated]
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress has a vulnerability that allows authenticated attackers with vendor level access to change user roles. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. The vulnerability has a high CVSS score of 8.1 and is considered a high priority due to its potent [truncated]
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25. This vulnerability allows authenticated attackers with Vendor-level access and above to modify the status of any order, delete or modify any post/product/page, regardless of ownership. The vulnerability exists due to missing validation on user-sup [truncated]