plugin

Wc Multivendor Marketplace Vulnerabilities

16 known security issues reported for the Wc Multivendor Marketplace WordPress plugin. Most recent disclosed Aug 17, 2026.

1 critical 1 high 8 medium

Running Wc Multivendor Marketplace on your site? Check whether your installed version is affected.

Scan your site free

WCFM Marketplace <= 3.8.0 - Insecure Direct Object Reference to Authenticated (Store vendor+) Cross-Vendor Review Deletion and Status Update

medium

The WCFM Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.0. This is due to missing ownership verification on the reviewid parameter in review status update and deletion functions. This makes it possible for authenticated attackers to delete or upd...

CVSS:
5.4
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Aug 17, 2026

CVE-2026-14196 on NVD →

WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'

medium

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Ve...

CVSS:
6.4
Affected:
up to 3.7.3
Fixed in:
3.7.4
Disclosed:
Jul 10, 2026

CVE-2026-12126 on NVD →

WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.2 - Authenticated (Store vendor+) SQL Injection

medium

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...

CVSS:
6.5
Affected:
up to 3.7.2
Fixed in:
3.7.3
Disclosed:
Apr 15, 2026

CVE-2025-63029 on NVD →

WCFM Marketplace <= 3.7.0 - Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation

medium

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0. This is due to the plugin not implementing authorization checks in the `wcfm-refund-requests-form` AJAX controller. This makes it possible fo...

CVSS:
5.3
Affected:
up to 3.7.0
Fixed in:
3.7.1
Disclosed:
Feb 9, 2026

CVE-2026-1722 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] <= 3.6.15 (unfixed)

unknown

[en] Missing Authorization vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Marketplace: from n/a through <= 3.6.15.

Affected:
up to 3.6.15
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-64631 on NVD →

WCFM Marketplace <= 3.7.3 - Missing Authorization

medium

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with store vendor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.7.3
Fixed in:
3.7.4
Disclosed:
Dec 15, 2025

CVE-2025-64631 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.6.12

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace allows Reflected XSS.This issue affects WCFM Marketplace: from n/a through 3.6.10.

Affected:
up to 3.6.12
Fixed in:
3.6.12
Disclosed:
Sep 17, 2024

CVE-2024-44009 on NVD →

WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.6.11 - Reflected Cross-Site Scripting

medium

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.6.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
6.1
Affected:
up to 3.6.11
Fixed in:
3.6.12
Disclosed:
Sep 16, 2024

CVE-2024-44009 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.6.3

unknown

[en] The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-leve...

Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Jan 11, 2024

CVE-2023-4960 on NVD →

WCFM Marketplace <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

CVSS:
6.4
Affected:
up to 3.6.2
Fixed in:
3.6.3
Disclosed:
Nov 23, 2023

CVE-2023-4960 on NVD →

WCFM Marketplace <= 3.4.11 - Missing Authorization

high

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a wide v...

CVSS:
8.8
Affected:
up to 3.4.11
Fixed in:
3.4.12
Disclosed:
Apr 5, 2023

CVE-2022-4935 on NVD →

WCFM Marketplace <= 3.4.12 - Cross-Site Request Forgery

medium

The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying shipping method details, modifyi...

CVSS:
6.3
Affected:
up to 3.4.12
Fixed in:
3.5.0
Disclosed:
Apr 5, 2023

CVE-2022-4936 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.5.0

unknown

[en] The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying shipping method details, mo...

Affected:
up to 3.5.0
Fixed in:
3.5.0
Disclosed:
Apr 5, 2023

CVE-2022-4936 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.4.12

unknown

[en] The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a w...

Affected:
up to 3.4.12
Fixed in:
3.4.12
Disclosed:
Apr 5, 2023

CVE-2022-4935 on NVD →

WCFM Marketplace &#8211; Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.4.12

unknown

[en] The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

Affected:
up to 3.4.12
Fixed in:
3.4.12
Disclosed:
Dec 21, 2021

CVE-2021-24849 on NVD →

WCFM - WooCommerce Multivendor Marketplace <= 3.4.11 - Unauthenticated SQL Injection

critical

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVSS:
9.8
Affected:
up to 3.4.11
Fixed in:
3.4.12
Disclosed:
Nov 22, 2021

CVE-2021-24849 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database