Impact
The WCFM Marketplace WordPress plugin versions before 3.8.1 allow a marketplace vendor to modify or permanently delete reviews that belong to other vendors' stores because ownership of a review is not verified before approval or removal. This flaw undermines the integrity of vendor feedback, potentially enabling defamation and eroding trust in the marketplace.
Affected Systems
All WordPress sites running the WCFM Marketplace plugin earlier than 3.8.1 are vulnerable, regardless of the installed theme or other plugins. Any vendor account with store‑management access to such a site can exploit the issue.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a low current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Exploitation requires only an authenticated vendor account, and no special environmental conditions are necessary. The vulnerability is an authorization weakness (CWE‑639).
OpenCVE Enrichment