Impact
The vulnerability in the WCFM – Frontend Manager permits an unauthenticated attacker to inject arbitrary reply content into any store inquiry. This is a CWE-862 missing authorization weakness: because the plugin does not verify that the requester is logged in or has the required permissions, a crafted request to the wcfm-my-account‑enquiry‑manage endpoint can overwrite the main inquiry record in wp_wcfm_enquiries and trigger email notifications to customers and vendors, directly compromising the integrity of customer communications.
Affected Systems
All WordPress sites running WCFM – Frontend Manager for WooCommerce from the vendor wclovers, with a version of 6.7.27 or earlier, are affected. The flaw resides in the wcfm-my-account‑enquiry‑manage controller and can be exploited on any store that hosts the vulnerable plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely. An attacker does not need to be authenticated; a simple HTTP request to the vulnerable endpoint with a crafted payload is sufficient to exploit the issue.
OpenCVE Enrichment