WordPress · Wcfm – Frontend Manager For Woocommerce · CVE-2026-10041
**Name of the Vulnerable Software and Affected Versions**
WCFM – Frontend Manager for WooCommerce versions prior to 6.7.28
**Description**
An Insecure Direct Object Reference (IDOR) exists in the `wcfm product archive` endpoint due to missing validation on a user-controlled key. This allows authenticated attackers with subscriber-level access or higher to archive products of arbitrary vendors, toggle the featured status of arbitrary listings, mark arbitrary WooCommerce orders as completed, and permanently delete bulk messages and enquiries belonging to other vendors.
**Recommendations**
Update WCFM – Frontend Manager for WooCommerce to version 6.7.28 or later.