Impact
Missing Authorization vulnerability in WC Lovers WCFM Marketplace plugin results in an access control flaw that allows an attacker to perform actions reserved for privileged users without proper checks. By exploiting incorrectly configured security levels, an attacker could gain unauthorized access to vendor or marketplace functions, potentially manipulating product listings, orders or financial data.
Affected Systems
Any WordPress site that uses the WC Lovers WCFM Marketplace plugin in a version through 3.7.1 is potentially affected. The flaw applies to all releases up to and including 3.7.1; earlier releases have no indication that they are safe, so site owners should verify whether their installation is within this range.
Risk and Exploitability
The CVSS base score of 4.9 indicates a moderate risk, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. The likely attack vector is remote via the WordPress web interface; an attacker could craft requests that bypass the missing access checks without special privileges. The official fix is to update to the latest plugin version.
OpenCVE Enrichment