Impact
The vulnerability in the WCFM Marketplace WordPress plugin allows an attacker to create refund requests without authentication or proof of ownership of an order. Once a refund request is submitted, store operators may process it, potentially issuing a credit or refund to the originating user without validating the requester's legitimacy. This flaw can lead to financial loss, fraud, and damage to user trust. The weakness originates from a failure to verify the identity or entitlement of the requester before permitting a refund operation.
Affected Systems
The flaw affects the WCFM Marketplace plugin for WordPress versions prior to 3.8.2. Any WordPress site deploying an earlier build of this plugin, particularly those that accept guest checkout orders, is susceptible. The issue does not appear in versions 3.8.2 and later.
Risk and Exploitability
Because the flaw is exploitable by unauthenticated web requests, the risk to any site using a vulnerable plugin is high. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. In practice, an attacker only needs to send a crafted refund request to the plugin’s endpoint, which the server will accept and process, leading to fraudulent refunds. The attack requires no authentication and therefore is likely to occur frequently if not mitigated.
OpenCVE Enrichment