WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
high
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it po...
- CVSS:
- 8.1
- Affected:
- up to 2.11.10
- Fixed in:
- 2.11.11
- Disclosed:
- Jul 7, 2026
CVE-2026-3688 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.10 - Missing Authorization
medium
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.11.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.11.10
- Fixed in:
- 2.11.11
- Disclosed:
- May 29, 2026
CVE-2026-42753 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment
medium
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it poss...
- CVSS:
- 4.3
- Affected:
- up to 2.11.8
- Fixed in:
- 2.11.9
- Disclosed:
- Feb 9, 2026
CVE-2025-15147 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.11.9
unknown
[en] The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it...
- Affected:
- up to 2.11.9
- Fixed in:
- 2.11.9
- Disclosed:
- Feb 9, 2026
CVE-2025-15147 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.11.0
unknown
[en] The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system re...
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.0
- Disclosed:
- May 20, 2023
CVE-2023-2276 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change
critical
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resourc...
- CVSS:
- 9.8
- Affected:
- up to 2.10.7
- Fixed in:
- 2.11.0
- Disclosed:
- May 3, 2023
CVE-2023-2276 on NVD →
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
critical
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membershi...
- CVSS:
- 9.8
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- Apr 5, 2023
CVE-2022-4939 on NVD →
WCFM Membership <= 2.10.0 - Missing Authorization
high
The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership...
- CVSS:
- 7.3
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.1
- Disclosed:
- Apr 5, 2023
CVE-2022-4940 on NVD →
WCFM Membership <= 2.9.10 - Cross-Site Request Forgery
medium
The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing rene...
- CVSS:
- 6.3
- Affected:
- up to 2.9.10
- Fixed in:
- 2.10.0
- Disclosed:
- Apr 5, 2023
CVE-2022-4941 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1
unknown
[en] THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the memb...
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.1
- Disclosed:
- Apr 5, 2023
CVE-2022-4939 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1
unknown
[en] The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membe...
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.1
- Disclosed:
- Apr 5, 2023
CVE-2022-4940 on NVD →
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1
unknown
[en] The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing...
- Affected:
- up to 2.10.1
- Fixed in:
- 2.10.1
- Disclosed:
- Apr 5, 2023
CVE-2022-4941 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database