Impact
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin is vulnerable to generic SQL injection through the wcfmmp_user_location_lng parameter. The plugin does not properly escape this user‑supplied value and fails to prepare the underlying SQL query, permitting attackers to inject arbitrary SQL code. When such a query executes, an unauthenticated user can read or modify sensitive information stored in the WordPress database, compromising confidentiality and integrity. This weakness is a classic input injection flaw identified as CWE‑89.
Affected Systems
All installations of the WCFM Marketplace plugin for WooCommerce released by Wclovers up through version 3.8.2 are susceptible. Any WordPress site that has this version of the plugin installed is at risk.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, although opportunity exists, the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is an unauthenticated, remote HTTP request that includes a crafted wcfmmp_user_location_lng parameter; no user credentials or privileged access are required to trigger the injection.
OpenCVE Enrichment