Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WCFM – Frontend Manager for WooCommerce — Vulnerabilities & Security Advisories 10

All 10 CVE vulnerabilities found in WCFM – Frontend Manager for WooCommerce, with AI-generated Chinese analysis, references, and POCs.

Vendor: wclovers

CVE ID Title CVSS Severity Published
CVE-2026-10041 WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers CWE-639 4.3 Medium 2026-07-11
CVE-2026-12994 WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller CWE-862 5.3 Medium 2026-07-11
CVE-2026-2554 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion CWE-639 8.1 High 2026-05-02
CVE-2026-4896 WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation CWE-639 8.1 High 2026-04-04
CVE-2026-0845 WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update CWE-862 7.2 High 2026-02-09
CVE-2025-54004 WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control vulnerability CWE-862 2.7 Low 2025-12-16
CVE-2025-3780 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification CWE-862 6.5 Medium 2025-07-08
CVE-2024-8290 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation CWE-639 8.8 High 2024-09-25
CVE-2024-29929 WordPress WCFM plugin <= 6.7.8 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-03-27
CVE-2022-4938 WCFM Frontend Manager <= 6.5.13 - Cross-Site Request Forgery CWE-352 6.3 Medium 2023-04-05

All 10 known CVE vulnerabilities affecting WCFM – Frontend Manager for WooCommerce with full Chinese analysis, references, and POCs where available.