Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wclovers — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting wclovers. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wclovers is a software component primarily used for content management and web application development, with 18 CVEs documenting its security history. Common vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and access control flaws. The component has faced multiple critical vulnerabilities that allowed attackers to bypass authentication or execute arbitrary code, particularly in versions prior to 2020. Security researchers have noted inconsistent patching practices and delayed remediation timelines for some issues. While recent versions show improved security controls, the historical vulnerability pattern suggests developers should implement strict input validation and keep implementations current to mitigate risks.

Found 6 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-18442 WCFM Marketplace <= 3.8.2 - Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-89 7.5 High 2026-09-18
CVE-2026-12126 WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title' — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-79 6.4 Medium 2026-07-11
CVE-2026-1722 WCFM Marketplace <= 3.7.0 - Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-862 5.3 Medium 2026-02-10
CVE-2023-4960 WCFM Marketplace <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-79 6.4 Medium 2024-01-11
CVE-2022-4936 WCFM Marketplace <= 3.4.12 - Cross-Site Request Forgery — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-352 6.3 Medium 2023-04-05
CVE-2022-4935 WCFM Marketplace <= 3.4.11 - Missing Authorization — WCFM Marketplace – Multivendor Marketplace for WooCommerce CWE-89 8.8 High 2023-04-05

This page lists every published CVE security advisory associated with wclovers. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.