Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wclovers — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting wclovers. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wclovers is a software component primarily used for content management and web application development, with 18 CVEs documenting its security history. Common vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and access control flaws. The component has faced multiple critical vulnerabilities that allowed attackers to bypass authentication or execute arbitrary code, particularly in versions prior to 2020. Security researchers have noted inconsistent patching practices and delayed remediation timelines for some issues. While recent versions show improved security controls, the historical vulnerability pattern suggests developers should implement strict input validation and keep implementations current to mitigate risks.

Found 8 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-10041 WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers — WCFM – Frontend Manager for WooCommerce CWE-639 4.3 Medium 2026-07-11
CVE-2026-12994 WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller — WCFM – Frontend Manager for WooCommerce CWE-862 5.3 Medium 2026-07-11
CVE-2026-2554 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion — WCFM – Frontend Manager for WooCommerce CWE-639 8.1 High 2026-05-02
CVE-2026-4896 WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation — WCFM – Frontend Manager for WooCommerce CWE-639 8.1 High 2026-04-04
CVE-2026-0845 WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update — WCFM – Frontend Manager for WooCommerce CWE-862 7.2 High 2026-02-09
CVE-2025-3780 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification — WCFM – Frontend Manager for WooCommerce CWE-862 6.5 Medium 2025-07-08
CVE-2024-8290 WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation — WCFM – Frontend Manager for WooCommerce CWE-639 8.8 High 2024-09-25
CVE-2022-4938 WCFM Frontend Manager <= 6.5.13 - Cross-Site Request Forgery — WCFM – Frontend Manager for WooCommerce CWE-352 6.3 Medium 2023-04-05

This page lists every published CVE security advisory associated with wclovers. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.