plugin

Wc Multivendor Membership Vulnerabilities

12 known security issues reported for the Wc Multivendor Membership WordPress plugin. Most recent disclosed Jul 7, 2026.

2 critical 2 high 3 medium

Running Wc Multivendor Membership on your site? Check whether your installed version is affected.

Scan your site free

WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite

high

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it po...

CVSS:
8.1
Affected:
up to 2.11.10
Fixed in:
2.11.11
Disclosed:
Jul 7, 2026

CVE-2026-3688 on NVD →

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.10 - Missing Authorization

medium

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.11.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.11.10
Fixed in:
2.11.11
Disclosed:
May 29, 2026

CVE-2026-42753 on NVD →

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment

medium

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it poss...

CVSS:
4.3
Affected:
up to 2.11.8
Fixed in:
2.11.9
Disclosed:
Feb 9, 2026

CVE-2025-15147 on NVD →

WCFM Membership &#8211; WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.11.9

unknown

[en] The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled key. This makes it...

Affected:
up to 2.11.9
Fixed in:
2.11.9
Disclosed:
Feb 9, 2026

CVE-2025-15147 on NVD →

WCFM Membership &#8211; WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.11.0

unknown

[en] The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system re...

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
May 20, 2023

CVE-2023-2276 on NVD →

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.10.7 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Password Change

critical

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resourc...

CVSS:
9.8
Affected:
up to 2.10.7
Fixed in:
2.11.0
Disclosed:
May 3, 2023

CVE-2023-2276 on NVD →

WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation

critical

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membershi...

CVSS:
9.8
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
Apr 5, 2023

CVE-2022-4939 on NVD →

WCFM Membership <= 2.10.0 - Missing Authorization

high

The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership...

CVSS:
7.3
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
Apr 5, 2023

CVE-2022-4940 on NVD →

WCFM Membership <= 2.9.10 - Cross-Site Request Forgery

medium

The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing rene...

CVSS:
6.3
Affected:
up to 2.9.10
Fixed in:
2.10.0
Disclosed:
Apr 5, 2023

CVE-2022-4941 on NVD →

WCFM Membership &#8211; WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1

unknown

[en] THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the memb...

Affected:
up to 2.10.1
Fixed in:
2.10.1
Disclosed:
Apr 5, 2023

CVE-2022-4939 on NVD →

WCFM Membership &#8211; WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1

unknown

[en] The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 2.10.0 due to missing capability checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membe...

Affected:
up to 2.10.1
Fixed in:
2.10.1
Disclosed:
Apr 5, 2023

CVE-2022-4940 on NVD →

WCFM Membership &#8211; WooCommerce Memberships for Multivendor Marketplace [wc-multivendor-membership] < 2.10.1

unknown

[en] The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying membership details, changing...

Affected:
up to 2.10.1
Fixed in:
2.10.1
Disclosed:
Apr 5, 2023

CVE-2022-4941 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database