Extension WordPress

Vulnérabilités WCFM – Frontend Manager for WooCommerce

Cette page rassemble les failles publiées pour WCFM – Frontend Manager for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WCFM – Frontend Manager for WooCommerce

12 fiches

CVE-2026-12994 Moyenne · 5,3
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce <= 6.7.27 – Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized to…

Versions affectées

*-6.7.27

Correctif

6.7.28

Publication

10/07/2026

CVE-2026-10041 Moyenne · 4,3
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce <= 6.7.27 – Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled key. This…

Versions affectées

*-6.7.27

Correctif

6.7.28

Publication

10/07/2026

CVE-2026-2554 Élevée · 8,1
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 – Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation…

Versions affectées

*-6.7.25

Correctif

6.7.26

Publication

01/05/2026

CVE-2026-4896 Élevée · 8,1
WCFM – Frontend Manager for WooCommerce

WCFM – WooCommerce Frontend Manager <= 6.7.25 – Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,…

Versions affectées

*-6.7.25

Correctif

6.7.26

Publication

03/04/2026

CVE-2026-0845 Élevée · 7,2
WCFM – Frontend Manager for WooCommerce

WCFM – WooCommerce Frontend Manager <= 6.7.24 – Authenticated (Shop Manager+) Arbitrary Options Update

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'WCFM_Settings_Controller::processing'…

Versions affectées

*-6.7.24

Correctif

6.7.25

Publication

09/02/2026

CVE-2025-3780 Moyenne · 6,5
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 – Missing Authorization to Unauthenticated Plugin Settings Modification

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to,…

Versions affectées

*-6.7.16

Correctif

6.7.17

Publication

08/07/2025

CVE-2024-8290 Élevée · 8,8
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 – Insecure Direct Object Reference to Account Takeover/Privilege Escalation

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing…

Versions affectées

*-6.7.12

Correctif

6.7.13

Publication

24/09/2024

CVE-2024-29929 Moyenne · 4,4
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce <= 6.7.8 – Authenticated (Shop manager+) Stored Cross-Site Scripting

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.7.8 due to insufficient input sanitization…

Versions affectées

*-6.7.8

Correctif

6.7.9

Publication

25/03/2024

CVE-2021-24835 Élevée · 8,8
WCFM – Frontend Manager for WooCommerce

WCFM – Frontend Manager for WooCommerce <= 6.5.11 – Customer/Subscriber+ SQL Injection

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM – WooCommerce Multivendor plugin such as WCFM – WooCommerce Multivendor Marketplace, does not escape…

Versions affectées

*-6.5.11

Correctif

6.5.12

Publication

11/10/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités