WordPress · Wcfm Marketplace · CVE-2026-12126
**Name of the Vulnerable Software and Affected Versions**
WCFM Marketplace – Multivendor Marketplace for WooCommerce versions prior to 3.7.4
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with Vendor-level access or higher to perform Stored Cross-Site Scripting. An attacker can inject arbitrary web scripts by uploading a media attachment with a crafted `post title` via the WordPress REST API endpoint '/wp-json/wp/v2/media'. The unescaped title is subsequently emitted within DataTables JSON and inserted as innerHTML when a privileged user loads the media dashboard, causing the script to execute in the user's browser.
**Recommendations**
Update WCFM Marketplace – Multivendor Marketplace for WooCommerce to version 3.7.4 or later.