Extension WordPress

Vulnérabilités WCFM Marketplace – Multivendor Marketplace for WooCommerce

Cette page rassemble les failles publiées pour WCFM Marketplace – Multivendor Marketplace for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
1Critiques
9Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WCFM Marketplace – Multivendor Marketplace for WooCommerce

9 fiches

CVE-2026-12126 Moyenne · 6,4
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM Marketplace <= 3.7.3 – Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.7.3

Correctif

3.7.4

Publication

10/07/2026

CVE-2025-63029 Moyenne · 6,5
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.2 – Authenticated (Store vendor+) SQL Injection

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

*-3.7.2

Correctif

3.7.3

Publication

15/04/2026

CVE-2026-1722 Moyenne · 5,3
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM Marketplace <= 3.7.0 – Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0. This is due to the plugin not implementing authorization checks in the…

Versions affectées

*-3.7.0

Correctif

3.7.1

Publication

09/02/2026

CVE-2024-44009 Moyenne · 6,1
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.6.11 – Reflected Cross-Site Scripting

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.6.11 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.6.11

Correctif

3.6.12

Publication

16/09/2024

CVE-2023-4960 Moyenne · 6,4
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM Marketplace <= 3.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-3.6.2

Correctif

3.6.3

Publication

23/11/2023

CVE-2021-24849 Critique · 9,8
WCFM Marketplace – Multivendor Marketplace for WooCommerce

WCFM – WooCommerce Multivendor Marketplace <= 3.4.11 – Unauthenticated SQL Injection

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

Versions affectées

*-3.4.11

Correctif

3.4.12

Publication

22/11/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités