Description
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete arbitrary enquiries and bulk messages belonging to other vendors.
Published: 2026-07-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WCFM – Frontend Manager for WooCommerce plugin contains an insecure direct object reference that permits authenticated users with subscriber-level access or higher to perform malicious data changes. Attackers can archive any vendor’s products, toggle the featured status of listings, mark orders as completed, and permanently delete enquiries and bulk messages belonging to other vendors, thereby undermining data integrity and disrupting normal shop operations.

Affected Systems

WordPress sites that have installed the WCFM – Frontend Manager for WooCommerce plugin from the WCLovers vendor in any version up to and including 6.7.27 are affected. Site administrators should verify the plugin version in use and prepare to apply the available fix.

Risk and Exploitability

The flaw is scored 4.3 on CVSS, indicating moderate severity, with an EPSS score of less than 1% and no listing in the CISA KEV catalog. The attack vector requires only authenticated access at the subscriber level, which is commonly granted. Although no public exploits have been reported, the logical vulnerability permits the attacker to trigger vulnerable AJAX endpoints and manipulate sensitive vendor data without proper authorization.

Generated by OpenCVE AI on July 29, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the WCLovers vendor site for any available patch or update for the WCFM – Frontend Manager for WooCommerce plugin and apply it as soon as possible.
  • Apply the principle of least privilege by restricting subscriber+ accounts to only those who legitimately need to modify vendor data, adjusting WordPress roles and capabilities accordingly.
  • Audit vendor, product, order, enquiry, and message records for unauthorized modifications and restore from backups if necessary; monitor server logs for anomalous AJAX activity against the wcfm_product_archive endpoint and other related handlers.

Generated by OpenCVE AI on July 29, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Wclovers
Wclovers wcfm – Frontend Manager For Woocommerce
Wordpress
Wordpress wordpress

Sat, 11 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to archive arbitrary vendors' products, toggle the featured status on arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete arbitrary enquiries and bulk messages belonging to other vendors.
Title WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wclovers Wcfm – Frontend Manager For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-13T14:39:33.538Z

Reserved: 2026-05-28T19:52:33.345Z

Link: CVE-2026-10041

cve-icon Vulnrichment

Updated: 2026-07-13T14:34:54.227Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:15:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key