PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4896 wclovers CVE debrief

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25. This vulnerability allows authenticated attackers with Vendor-level access and above to modify the status of any order, delete or modify any post/product/page, regardless of ownership. The vulnerability exists due to missing validation on user-supplied object IDs in multiple AJAX actions, including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller. This issue has a high impact on the security of WordPress installations using the affected plugin.

Vendor
wclovers
Product
WCFM – Frontend Manager for WooCommerce
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-07-21
Advisory published
2026-04-04
Advisory updated
2026-07-21

Who should care

Authenticated attackers with Vendor-level access and above could exploit this vulnerability to modify the status of any order, delete or modify any post/product/page, regardless of ownership. This vulnerability has a significant impact on the security of WordPress installations using the affected plugin, particularly those with multiple users or high-value assets. Security teams and administrators responsible for WordPress installations should prioritize remediation and implement additional monitoring and compensating controls to mitigate the risk.

Technical summary

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This makes it possible for authenticated attackers, with Vendor-level access and above, to modify the status of any order, delete or modify any post/product/page, regardless of ownership. The vulnerability is a result of inadequate input validation and sanitization of user-supplied object IDs.

Defensive priority

High

Recommended defensive actions

  • Inventory and verify the WCFM – Frontend Manager for WooCommerce plugin version.
  • Restrict Vendor-level access and above to necessary personnel.
  • Implement additional monitoring for suspicious AJAX actions.
  • Consider compensating controls such as Web Application Firewalls.
  • Apply vendor remediation when available.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-04-04T08:16:06.543Z and was last modified on 2026-07-21T19:10:00.107Z. The NVD entry is currently Deferred. The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, `delete_wcfm_product`, and the article management controller due to missing validation on user-supplied object IDs. This information is based on the CVE record and NVD entry, which may not be comprehensive. Defenders should verify the affected scope and severity with the official advisory or CVE record.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-04T08:16:06.543Z and has not been modified since then. The NVD entry is currently Deferred.