PT-2026-78276 · WordPress · Wcfm Marketplace
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WCFM Marketplace WordPress plugin versions prior to 3.8.1
Description
The plugin fails to verify if a marketplace vendor owns a review before permitting it to be unapproved or deleted. This allows any vendor to modify or permanently delete reviews associated with stores belonging to other vendors.
Recommendations
Update the WCFM Marketplace WordPress plugin to version 3.8.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wcfm Marketplace