WCFM Marketplace <= 3.8.0 - Insecure Direct Object Reference to Authenticated (Store vendor+) Cross-Vendor Review Deletion and Status Update
medium
The WCFM Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.0. This is due to missing ownership verification on the reviewid parameter in review status update and deletion functions. This makes it possible for authenticated attackers to delete or upd...
- CVSS:
- 5.4
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Aug 17, 2026
CVE-2026-14196 on NVD →
WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'
medium
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Ve...
- CVSS:
- 6.4
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Jul 10, 2026
CVE-2026-12126 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.2 - Authenticated (Store vendor+) SQL Injection
medium
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 6.5
- Affected:
- up to 3.7.2
- Fixed in:
- 3.7.3
- Disclosed:
- Apr 15, 2026
CVE-2025-63029 on NVD →
WCFM Marketplace <= 3.7.0 - Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation
medium
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0. This is due to the plugin not implementing authorization checks in the `wcfm-refund-requests-form` AJAX controller. This makes it possible fo...
- CVSS:
- 5.3
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1
- Disclosed:
- Feb 9, 2026
CVE-2026-1722 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] <= 3.6.15 (unfixed)
unknown
[en] Missing Authorization vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Marketplace: from n/a through <= 3.6.15.
- Affected:
- up to 3.6.15
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-64631 on NVD →
WCFM Marketplace <= 3.7.3 - Missing Authorization
medium
The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with store vendor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Dec 15, 2025
CVE-2025-64631 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.6.12
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace allows Reflected XSS.This issue affects WCFM Marketplace: from n/a through 3.6.10.
- Affected:
- up to 3.6.12
- Fixed in:
- 3.6.12
- Disclosed:
- Sep 17, 2024
CVE-2024-44009 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.6.11 - Reflected Cross-Site Scripting
medium
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.6.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- CVSS:
- 6.1
- Affected:
- up to 3.6.11
- Fixed in:
- 3.6.12
- Disclosed:
- Sep 16, 2024
CVE-2024-44009 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.6.3
unknown
[en] The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-leve...
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.3
- Disclosed:
- Jan 11, 2024
CVE-2023-4960 on NVD →
WCFM Marketplace <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- CVSS:
- 6.4
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- Nov 23, 2023
CVE-2023-4960 on NVD →
WCFM Marketplace <= 3.4.11 - Missing Authorization
high
The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a wide v...
- CVSS:
- 8.8
- Affected:
- up to 3.4.11
- Fixed in:
- 3.4.12
- Disclosed:
- Apr 5, 2023
CVE-2022-4935 on NVD →
WCFM Marketplace <= 3.4.12 - Cross-Site Request Forgery
medium
The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying shipping method details, modifyi...
- CVSS:
- 6.3
- Affected:
- up to 3.4.12
- Fixed in:
- 3.5.0
- Disclosed:
- Apr 5, 2023
CVE-2022-4936 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.5.0
unknown
[en] The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying shipping method details, mo...
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Apr 5, 2023
CVE-2022-4936 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.4.12
unknown
[en] The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a w...
- Affected:
- up to 3.4.12
- Fixed in:
- 3.4.12
- Disclosed:
- Apr 5, 2023
CVE-2022-4935 on NVD →
WCFM Marketplace – Multivendor Marketplace for WooCommerce [wc-multivendor-marketplace] < 3.4.12
unknown
[en] The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
- Affected:
- up to 3.4.12
- Fixed in:
- 3.4.12
- Disclosed:
- Dec 21, 2021
CVE-2021-24849 on NVD →
WCFM - WooCommerce Multivendor Marketplace <= 3.4.11 - Unauthenticated SQL Injection
critical
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
- CVSS:
- 9.8
- Affected:
- up to 3.4.11
- Fixed in:
- 3.4.12
- Disclosed:
- Nov 22, 2021
CVE-2021-24849 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database