WordPress WCFM是WordPress基金会的一个智能前端控制面板组件。 WordPress WCFM 6.7.27及之前版本存在授权问题漏洞,该漏洞源于通过wcfm_product_archive对用户控制键缺少验证,导致不安全的直接对象引用,使得经过身份验证的攻击者(具有订阅者级别及以上权限)能够归档任意供应商的产品、切换任意列表的精选状态、将任意WooCommerce订单标记为已完成,并永久删除属于其他供应商的任意查询和批量消息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wclovers | WCFM – Frontend Manager for WooCommerce | ≤ 6.7.27 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wclovers | WCFM – Frontend Manager for WooCommerce | 0 ~ 6.7.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12126 | 6.4 MEDIUM | WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attach |
| CVE-2026-12994 | 5.3 MEDIUM | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticat |
No comments yet