PatchSiren

wclovers CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wclovers CVE published 2026-07-11

CVE-2026-12994

The WCFM – Frontend Manager for WooCommerce plugin for WordPress has an authorization bypass vulnerability in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. As a result, unauthenticated attackers can inject arbitrary reply content into any store inquiry, overwrite the main inquiry record in wp_wcfm_enquiries, and [truncated]

MEDIUM wclovers CVE published 2026-07-11

CVE-2026-12126

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Vendor-level access and above, to inject arbitrary web scripts in pages that will execute [truncated]

MEDIUM wclovers CVE published 2026-07-11

CVE-2026-10041

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This vulnerability allows authenticated attackers with subscriber-level access and above to archive arbitrary vendors' products, toggle the featured status on arbitrar [truncated]

HIGH wclovers CVE published 2026-07-08

CVE-2026-3688

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress has a vulnerability that allows authenticated attackers with vendor level access to change user roles. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. The vulnerability has a high CVSS score of 8.1 and is considered a high priority due to its potent [truncated]

HIGH wclovers CVE published 2026-04-04

CVE-2026-4896

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25. This vulnerability allows authenticated attackers with Vendor-level access and above to modify the status of any order, delete or modify any post/product/page, regardless of ownership. The vulnerability exists due to missing validation on user-sup [truncated]