WordPress WCFM Marketplace是WordPress基金会的一款多供应商电子商务市场组件。 WordPress WCFM Marketplace 3.7.3及之前版本存在跨站脚本漏洞,该漏洞源于输入清理和输出转义不足,可能导致经过身份验证的攻击者(具有Vendor级别及以上权限)通过附件“post_title”注入存储型跨站脚本,在用户访问受影响的页面时执行任意Web脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | ≤ 3.7.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | 0 ~ 3.7.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12994 | 5.3 MEDIUM | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticat |
| CVE-2026-10041 | 4.3 MEDIUM | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Au |
No comments yet