Impact
The WCFM – Frontend Manager for WooCommerce plugin contains an insecure direct object reference that permits authenticated users with subscriber-level access or higher to perform malicious data changes. Attackers can archive any vendor’s products, toggle the featured status of listings, mark orders as completed, and permanently delete enquiries and bulk messages belonging to other vendors, thereby undermining data integrity and disrupting normal shop operations.
Affected Systems
WordPress sites that have installed the WCFM – Frontend Manager for WooCommerce plugin from the WCLovers vendor in any version up to and including 6.7.27 are affected. Site administrators should verify the plugin version in use and prepare to apply the available fix.
Risk and Exploitability
The flaw is scored 4.3 on CVSS, indicating moderate severity, with an EPSS score of less than 1% and no listing in the CISA KEV catalog. The attack vector requires only authenticated access at the subscriber level, which is commonly granted. Although no public exploits have been reported, the logical vulnerability permits the attacker to trigger vulnerable AJAX endpoints and manipulate sensitive vendor data without proper authorization.
OpenCVE Enrichment