Description
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.
Published: 2026-07-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WCFM Membership plugin is an insecure direct object reference that allows an authenticated user with vendor level or higher access to change another user’s role to 'wcfm_vendor' by manipulating the membership plan via the 'wcfmvm_membership_change' AJAX action escalation (CWE‑639) because the attacker can bestow vendor privileges on an arbitrary account without the description detailing the specific capabilities of the 'wcfm_vendor' role, but providing that role is recognized as an escalation of privileges.

Affected Systems

WordPress installations that use the WCFM Membership – WooCommerce Membership plugin10 marketplace with the plugin deployed in one of these releases must verify their current plugin version.

Risk and Exploitability

The flaw has a CVSS score of 8.1, indicating high severity. The EPSS score of < 1% suggests a very low probability of exploitation at present, and the vulnerability has not been listed in the CISA KEV catalog. Based on the description, the attack vector requires an authenticated user with vendor-level or higher privileges; the attacker manipulates the AJAX action to overwrite user roles. Successful exploitation allows the attacker to assume vendor‑level privileges, which is a limited privilege escalation.

Generated by OpenCVE AI on July 26, 2026 at 18:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WCFM Membership to any version newer than 2.11.10, which removes the flaw in the 'wcfmvm_membership_change' AJAX action
  • Limit the execution of the 'wcfmvm_membership_change' AJAX action to administrator accounts only, so that only users with the highest privilege can invoke role changes
  • Review the current user roles within your WordPress installation and remove any vendor roles that were granted unintentionally by unauthorized users

Generated by OpenCVE AI on July 26, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wclovers
Wclovers wcfm Membership – Woocommerce Memberships For Multivendor Marketplace
Wordpress
Wordpress wordpress
Vendors & Products Wclovers
Wclovers wcfm Membership – Woocommerce Memberships For Multivendor Marketplace
Wordpress
Wordpress wordpress

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' AJAX action not validating user permission to modify other users. This makes it possible for authenticated attackers, with vendor level access and above, to change any user's role to 'wcfm_vendor' by changing their membership plan.
Title WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Wclovers Wcfm Membership – Woocommerce Memberships For Multivendor Marketplace
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-08T15:01:02.908Z

Reserved: 2026-03-06T23:43:39.850Z

Link: CVE-2026-3688

cve-icon Vulnrichment

Updated: 2026-07-08T15:00:58.906Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:15:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key