Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nadir Şensoy

#44812of 56,335
6.4Total CVSS
Vulnerabilities · 1
PT-2026-57412
6.4
2026-07-11
WordPress · Wcfm Marketplace · CVE-2026-12126
**Name of the Vulnerable Software and Affected Versions** WCFM Marketplace – Multivendor Marketplace for WooCommerce versions prior to 3.7.4 **Description** Insufficient input sanitization and output escaping allow authenticated attackers with Vendor-level access or higher to perform Stored Cross-Site Scripting. An attacker can inject arbitrary web scripts by uploading a media attachment with a crafted `post title` via the WordPress REST API endpoint '/wp-json/wp/v2/media'. The unescaped title is subsequently emitted within DataTables JSON and inserted as innerHTML when a privileged user loads the media dashboard, causing the script to execute in the user's browser. **Recommendations** Update WCFM Marketplace – Multivendor Marketplace for WooCommerce to version 3.7.4 or later.